[ALPINE:CVE-2023-1999] libwebp, firefox-esr vulnerability
Severity
High
Fixed Packages
81
CVEs
1
[From CVE-2023-1999] There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
- ID
- ALPINE:CVE-2023-1999
- Severity
- high
- Severity from
- CVE-2023-1999
- URL
- https://security.alpinelinux.org/vuln/CVE-2023-1999
- Published
-
2023-06-20T12:15:09
(15 months ago) - Modified
-
2023-06-20T12:15:09
(15 months ago) - Rights
- Alpine Linux Security Team
- Other Advisories
-
- ALAS2-2023-2028
- ALSA-2023:2076
- ALSA-2023:2078
- DSA-5385-1
- DSA-5392-1
- DSA-5408-1
- ELSA-2023-2076
- ELSA-2023-2077
- ELSA-2023-2078
- GLSA-202305-35
- GLSA-202305-36
- GLSA-202309-05
- MFSA-2023-13
- MFSA-2023-14
- MFSA-2023-15
- MS:CVE-2023-1999
- RHSA-2023:1786
- RHSA-2023:1787
- RHSA-2023:1791
- RHSA-2023:1802
- RHSA-2023:1806
- RHSA-2023:1809
- RHSA-2023:2076
- RHSA-2023:2077
- RHSA-2023:2078
- RLSA-2023:2076
- RLSA-2023:2078
- SUSE-SU-2023:2064-1
- SUSE-SU-2023:2467-1
- SUSE-SU-2023:2490-1
- SUSE-SU-2023:2552-1
- USN-6078-1
- USN-6078-2
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Fixed | pkg:apk/alpine/libwebp?arch=x86_64&distro=alpine-edge | alpine | libwebp | = 1.3.0-r3 | alpine-edge | x86_64 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86_64&distro=alpine-3.20 | alpine | libwebp | = 1.3.0-r3 | alpine-3.20 | x86_64 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86_64&distro=alpine-3.19 | alpine | libwebp | = 1.3.0-r3 | alpine-3.19 | x86_64 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86_64&distro=alpine-3.18 | alpine | libwebp | = 1.3.0-r2 | alpine-3.18 | x86_64 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86_64&distro=alpine-3.17 | alpine | libwebp | = 1.2.4-r2 | alpine-3.17 | x86_64 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86_64&distro=alpine-3.16 | alpine | libwebp | = 1.2.3-r1 | alpine-3.16 | x86_64 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86_64&distro=alpine-3.15 | alpine | libwebp | = 1.2.2-r1 | alpine-3.15 | x86_64 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86&distro=alpine-edge | alpine | libwebp | = 1.3.0-r3 | alpine-edge | x86 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86&distro=alpine-3.20 | alpine | libwebp | = 1.3.0-r3 | alpine-3.20 | x86 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86&distro=alpine-3.19 | alpine | libwebp | = 1.3.0-r3 | alpine-3.19 | x86 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86&distro=alpine-3.18 | alpine | libwebp | = 1.3.0-r2 | alpine-3.18 | x86 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86&distro=alpine-3.17 | alpine | libwebp | = 1.2.4-r2 | alpine-3.17 | x86 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86&distro=alpine-3.16 | alpine | libwebp | = 1.2.3-r1 | alpine-3.16 | x86 | |
Fixed | pkg:apk/alpine/libwebp?arch=x86&distro=alpine-3.15 | alpine | libwebp | = 1.2.2-r1 | alpine-3.15 | x86 | |
Fixed | pkg:apk/alpine/libwebp?arch=s390x&distro=alpine-edge | alpine | libwebp | = 1.3.0-r3 | alpine-edge | s390x | |
Fixed | pkg:apk/alpine/libwebp?arch=s390x&distro=alpine-3.20 | alpine | libwebp | = 1.3.0-r3 | alpine-3.20 | s390x | |
Fixed | pkg:apk/alpine/libwebp?arch=s390x&distro=alpine-3.19 | alpine | libwebp | = 1.3.0-r3 | alpine-3.19 | s390x | |
Fixed | pkg:apk/alpine/libwebp?arch=s390x&distro=alpine-3.18 | alpine | libwebp | = 1.3.0-r2 | alpine-3.18 | s390x | |
Fixed | pkg:apk/alpine/libwebp?arch=s390x&distro=alpine-3.17 | alpine | libwebp | = 1.2.4-r2 | alpine-3.17 | s390x | |
Fixed | pkg:apk/alpine/libwebp?arch=s390x&distro=alpine-3.16 | alpine | libwebp | = 1.2.3-r1 | alpine-3.16 | s390x | |
Fixed | pkg:apk/alpine/libwebp?arch=s390x&distro=alpine-3.15 | alpine | libwebp | = 1.2.2-r1 | alpine-3.15 | s390x | |
Fixed | pkg:apk/alpine/libwebp?arch=riscv64&distro=alpine-edge | alpine | libwebp | = 1.3.0-r3 | alpine-edge | riscv64 | |
Fixed | pkg:apk/alpine/libwebp?arch=riscv64&distro=alpine-3.20 | alpine | libwebp | = 1.3.0-r3 | alpine-3.20 | riscv64 | |
Fixed | pkg:apk/alpine/libwebp?arch=ppc64le&distro=alpine-edge | alpine | libwebp | = 1.3.0-r3 | alpine-edge | ppc64le | |
Fixed | pkg:apk/alpine/libwebp?arch=ppc64le&distro=alpine-3.20 | alpine | libwebp | = 1.3.0-r3 | alpine-3.20 | ppc64le | |
Fixed | pkg:apk/alpine/libwebp?arch=ppc64le&distro=alpine-3.19 | alpine | libwebp | = 1.3.0-r3 | alpine-3.19 | ppc64le | |
Fixed | pkg:apk/alpine/libwebp?arch=ppc64le&distro=alpine-3.18 | alpine | libwebp | = 1.3.0-r2 | alpine-3.18 | ppc64le | |
Fixed | pkg:apk/alpine/libwebp?arch=ppc64le&distro=alpine-3.17 | alpine | libwebp | = 1.2.4-r2 | alpine-3.17 | ppc64le | |
Fixed | pkg:apk/alpine/libwebp?arch=ppc64le&distro=alpine-3.16 | alpine | libwebp | = 1.2.3-r1 | alpine-3.16 | ppc64le | |
Fixed | pkg:apk/alpine/libwebp?arch=ppc64le&distro=alpine-3.15 | alpine | libwebp | = 1.2.2-r1 | alpine-3.15 | ppc64le | |
Fixed | pkg:apk/alpine/libwebp?arch=armv7&distro=alpine-edge | alpine | libwebp | = 1.3.0-r3 | alpine-edge | armv7 | |
Fixed | pkg:apk/alpine/libwebp?arch=armv7&distro=alpine-3.20 | alpine | libwebp | = 1.3.0-r3 | alpine-3.20 | armv7 | |
Fixed | pkg:apk/alpine/libwebp?arch=armv7&distro=alpine-3.19 | alpine | libwebp | = 1.3.0-r3 | alpine-3.19 | armv7 | |
Fixed | pkg:apk/alpine/libwebp?arch=armv7&distro=alpine-3.18 | alpine | libwebp | = 1.3.0-r2 | alpine-3.18 | armv7 | |
Fixed | pkg:apk/alpine/libwebp?arch=armv7&distro=alpine-3.17 | alpine | libwebp | = 1.2.4-r2 | alpine-3.17 | armv7 | |
Fixed | pkg:apk/alpine/libwebp?arch=armv7&distro=alpine-3.16 | alpine | libwebp | = 1.2.3-r1 | alpine-3.16 | armv7 | |
Fixed | pkg:apk/alpine/libwebp?arch=armv7&distro=alpine-3.15 | alpine | libwebp | = 1.2.2-r1 | alpine-3.15 | armv7 | |
Fixed | pkg:apk/alpine/libwebp?arch=armhf&distro=alpine-edge | alpine | libwebp | = 1.3.0-r3 | alpine-edge | armhf | |
Fixed | pkg:apk/alpine/libwebp?arch=armhf&distro=alpine-3.20 | alpine | libwebp | = 1.3.0-r3 | alpine-3.20 | armhf | |
Fixed | pkg:apk/alpine/libwebp?arch=armhf&distro=alpine-3.19 | alpine | libwebp | = 1.3.0-r3 | alpine-3.19 | armhf | |
Fixed | pkg:apk/alpine/libwebp?arch=armhf&distro=alpine-3.18 | alpine | libwebp | = 1.3.0-r2 | alpine-3.18 | armhf | |
Fixed | pkg:apk/alpine/libwebp?arch=armhf&distro=alpine-3.17 | alpine | libwebp | = 1.2.4-r2 | alpine-3.17 | armhf | |
Fixed | pkg:apk/alpine/libwebp?arch=armhf&distro=alpine-3.16 | alpine | libwebp | = 1.2.3-r1 | alpine-3.16 | armhf | |
Fixed | pkg:apk/alpine/libwebp?arch=armhf&distro=alpine-3.15 | alpine | libwebp | = 1.2.2-r1 | alpine-3.15 | armhf | |
Fixed | pkg:apk/alpine/libwebp?arch=aarch64&distro=alpine-edge | alpine | libwebp | = 1.3.0-r3 | alpine-edge | aarch64 | |
Fixed | pkg:apk/alpine/libwebp?arch=aarch64&distro=alpine-3.20 | alpine | libwebp | = 1.3.0-r3 | alpine-3.20 | aarch64 | |
Fixed | pkg:apk/alpine/libwebp?arch=aarch64&distro=alpine-3.19 | alpine | libwebp | = 1.3.0-r3 | alpine-3.19 | aarch64 | |
Fixed | pkg:apk/alpine/libwebp?arch=aarch64&distro=alpine-3.18 | alpine | libwebp | = 1.3.0-r2 | alpine-3.18 | aarch64 | |
Fixed | pkg:apk/alpine/libwebp?arch=aarch64&distro=alpine-3.17 | alpine | libwebp | = 1.2.4-r2 | alpine-3.17 | aarch64 | |
Fixed | pkg:apk/alpine/libwebp?arch=aarch64&distro=alpine-3.16 | alpine | libwebp | = 1.2.3-r1 | alpine-3.16 | aarch64 | |
Fixed | pkg:apk/alpine/libwebp?arch=aarch64&distro=alpine-3.15 | alpine | libwebp | = 1.2.2-r1 | alpine-3.15 | aarch64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=x86_64&distro=alpine-edge | alpine | firefox-esr | = 102.10.0-r0 | alpine-edge | x86_64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=x86_64&distro=alpine-3.20 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.20 | x86_64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=x86_64&distro=alpine-3.19 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.19 | x86_64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=x86_64&distro=alpine-3.18 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.18 | x86_64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=x86&distro=alpine-edge | alpine | firefox-esr | = 102.10.0-r0 | alpine-edge | x86 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=x86&distro=alpine-3.20 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.20 | x86 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=x86&distro=alpine-3.19 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.19 | x86 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=x86&distro=alpine-3.18 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.18 | x86 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=s390x&distro=alpine-edge | alpine | firefox-esr | = 102.10.0-r0 | alpine-edge | s390x | |
Fixed | pkg:apk/alpine/firefox-esr?arch=s390x&distro=alpine-3.20 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.20 | s390x | |
Fixed | pkg:apk/alpine/firefox-esr?arch=s390x&distro=alpine-3.19 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.19 | s390x | |
Fixed | pkg:apk/alpine/firefox-esr?arch=s390x&distro=alpine-3.18 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.18 | s390x | |
Fixed | pkg:apk/alpine/firefox-esr?arch=riscv64&distro=alpine-edge | alpine | firefox-esr | = 102.10.0-r0 | alpine-edge | riscv64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=riscv64&distro=alpine-3.20 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.20 | riscv64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=ppc64le&distro=alpine-edge | alpine | firefox-esr | = 102.10.0-r0 | alpine-edge | ppc64le | |
Fixed | pkg:apk/alpine/firefox-esr?arch=ppc64le&distro=alpine-3.20 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.20 | ppc64le | |
Fixed | pkg:apk/alpine/firefox-esr?arch=ppc64le&distro=alpine-3.19 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.19 | ppc64le | |
Fixed | pkg:apk/alpine/firefox-esr?arch=ppc64le&distro=alpine-3.18 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.18 | ppc64le | |
Fixed | pkg:apk/alpine/firefox-esr?arch=armv7&distro=alpine-edge | alpine | firefox-esr | = 102.10.0-r0 | alpine-edge | armv7 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=armv7&distro=alpine-3.20 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.20 | armv7 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=armv7&distro=alpine-3.19 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.19 | armv7 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=armv7&distro=alpine-3.18 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.18 | armv7 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=armhf&distro=alpine-edge | alpine | firefox-esr | = 102.10.0-r0 | alpine-edge | armhf | |
Fixed | pkg:apk/alpine/firefox-esr?arch=armhf&distro=alpine-3.20 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.20 | armhf | |
Fixed | pkg:apk/alpine/firefox-esr?arch=armhf&distro=alpine-3.19 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.19 | armhf | |
Fixed | pkg:apk/alpine/firefox-esr?arch=armhf&distro=alpine-3.18 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.18 | armhf | |
Fixed | pkg:apk/alpine/firefox-esr?arch=aarch64&distro=alpine-edge | alpine | firefox-esr | = 102.10.0-r0 | alpine-edge | aarch64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=aarch64&distro=alpine-3.20 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.20 | aarch64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=aarch64&distro=alpine-3.19 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.19 | aarch64 | |
Fixed | pkg:apk/alpine/firefox-esr?arch=aarch64&distro=alpine-3.18 | alpine | firefox-esr | = 102.10.0-r0 | alpine-3.18 | aarch64 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |