[USN-6078-2] libwebp vulnerability

Severity High
Affected Packages 5
CVEs 1

libwebp could be made to crash or run programs as your login if it opened a specially crafted file.

USN-6078-1 fixed a vulnerability in libwebp. This update
provides the corresponding update for Ubuntu 16.04 LTS.

Original advisory details:

Irvan Kurniawan discovered that libwebp incorrectly handled certain memory
operations. If a user or automated system were tricked into opening a
specially crafted image file, a remote attacker could use this issue to
cause libwebp to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Package Affected Version
pkg:deb/ubuntu/webp?distro=xenial < 0.4.4-1ubuntu0.1~esm2
pkg:deb/ubuntu/libwebpmux1?distro=xenial < 0.4.4-1ubuntu0.1~esm2
pkg:deb/ubuntu/libwebpdemux1?distro=xenial < 0.4.4-1ubuntu0.1~esm2
pkg:deb/ubuntu/libwebp5?distro=xenial < 0.4.4-1ubuntu0.1~esm2
pkg:deb/ubuntu/libwebp-dev?distro=xenial < 0.4.4-1ubuntu0.1~esm2
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/webp?distro=xenial ubuntu webp < 0.4.4-1ubuntu0.1~esm2 xenial
Affected pkg:deb/ubuntu/libwebpmux1?distro=xenial ubuntu libwebpmux1 < 0.4.4-1ubuntu0.1~esm2 xenial
Affected pkg:deb/ubuntu/libwebpdemux1?distro=xenial ubuntu libwebpdemux1 < 0.4.4-1ubuntu0.1~esm2 xenial
Affected pkg:deb/ubuntu/libwebp5?distro=xenial ubuntu libwebp5 < 0.4.4-1ubuntu0.1~esm2 xenial
Affected pkg:deb/ubuntu/libwebp-dev?distro=xenial ubuntu libwebp-dev < 0.4.4-1ubuntu0.1~esm2 xenial
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...