CVE-2023-5217
28.09.2023, 16:15
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)Enginsight
| Vendor | Product | Version |
|---|---|---|
| webmproject | libvpx | 𝑥 < 1.13.1 |
| microsoft | edge | 116.0.1938.98 |
| microsoft | edge | 117.0.2045.47 |
| microsoft | edge_chromium | 116.0.5845.229 |
| microsoft | edge_chromium | 117.0.5938.132 |
| mozilla | firefox | 𝑥 < 115.3.1 |
| mozilla | firefox | 𝑥 < 118.0.1 |
| mozilla | thunderbird | 𝑥 < 115.3.1 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
| debian | debian_linux | 12.0 |
| apple | ipados | 17.0 ≤ 𝑥 < 17.0.3 |
| apple | ipados | 16.7 |
| apple | iphone_os | 17.0 ≤ 𝑥 < 17.0.3 |
| apple | iphone_os | 16.7 |
| chrome | 𝑥 < 117.0.5938.132 | |
| redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium |
| ||||||||||||
| firefox |
| ||||||||||||
| firefox-esr |
| ||||||||||||
| libvpx |
| ||||||||||||
| thunderbird |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| chromium-browser |
| ||||||||||||||||||
| firefox |
| ||||||||||||||||||
| libvpx |
| ||||||||||||||||||
| mozjs102 |
| ||||||||||||||||||
| mozjs38 |
| ||||||||||||||||||
| mozjs52 |
| ||||||||||||||||||
| mozjs68 |
| ||||||||||||||||||
| mozjs78 |
| ||||||||||||||||||
| mozjs91 |
| ||||||||||||||||||
| thunderbird |
|
Common Weakness Enumeration
References