CVE-2023-5217
28.09.2023, 16:15
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)Enginsight
Vendor | Product | Version |
---|---|---|
webmproject | libvpx | 𝑥 < 1.13.1 |
microsoft | edge | 116.0.1938.98 |
microsoft | edge | 117.0.2045.47 |
microsoft | edge_chromium | 116.0.5845.229 |
microsoft | edge_chromium | 117.0.5938.132 |
mozilla | firefox | 𝑥 < 115.3.1 |
mozilla | firefox | 𝑥 < 118.0.1 |
mozilla | thunderbird | 𝑥 < 115.3.1 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
debian | debian_linux | 12.0 |
apple | ipados | 17.0 ≤ 𝑥 < 17.0.3 |
apple | ipados | 16.7 |
apple | iphone_os | 17.0 ≤ 𝑥 < 17.0.3 |
apple | iphone_os | 16.7 |
chrome | 𝑥 < 117.0.5938.132 | |
redhat | enterprise_linux | 9.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium |
| ||||||||||||
firefox |
| ||||||||||||
firefox-esr |
| ||||||||||||
libvpx |
| ||||||||||||
thunderbird |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
chromium-browser |
| ||||||||||||||||||
firefox |
| ||||||||||||||||||
libvpx |
| ||||||||||||||||||
mozjs102 |
| ||||||||||||||||||
mozjs38 |
| ||||||||||||||||||
mozjs52 |
| ||||||||||||||||||
mozjs68 |
| ||||||||||||||||||
mozjs78 |
| ||||||||||||||||||
mozjs91 |
| ||||||||||||||||||
thunderbird |
|
Common Weakness Enumeration
References