[USN-6369-1] libwebp vulnerability

Severity High
Affected Packages 15
CVEs 1

libwebp could be made to crash or run programs if it opened a specially crafted file.

It was discovered that libwebp incorrectly handled certain malformed
images. If a user or automated system were tricked into opening a
specially crafted image file, a remote attacker could use this issue to
cause libwebp to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Package Affected Version
pkg:deb/ubuntu/webp?distro=lunar < 1.2.4-0.1ubuntu0.23.04.2
pkg:deb/ubuntu/webp?distro=jammy < 1.2.2-2ubuntu0.22.04.2
pkg:deb/ubuntu/webp?distro=focal < 0.6.1-2ubuntu0.20.04.3
pkg:deb/ubuntu/libwebpmux3?distro=lunar < 1.2.4-0.1ubuntu0.23.04.2
pkg:deb/ubuntu/libwebpmux3?distro=jammy < 1.2.2-2ubuntu0.22.04.2
pkg:deb/ubuntu/libwebpmux3?distro=focal < 0.6.1-2ubuntu0.20.04.3
pkg:deb/ubuntu/libwebpdemux2?distro=lunar < 1.2.4-0.1ubuntu0.23.04.2
pkg:deb/ubuntu/libwebpdemux2?distro=jammy < 1.2.2-2ubuntu0.22.04.2
pkg:deb/ubuntu/libwebpdemux2?distro=focal < 0.6.1-2ubuntu0.20.04.3
pkg:deb/ubuntu/libwebp7?distro=lunar < 1.2.4-0.1ubuntu0.23.04.2
pkg:deb/ubuntu/libwebp7?distro=jammy < 1.2.2-2ubuntu0.22.04.2
pkg:deb/ubuntu/libwebp6?distro=focal < 0.6.1-2ubuntu0.20.04.3
pkg:deb/ubuntu/libwebp-dev?distro=lunar < 1.2.4-0.1ubuntu0.23.04.2
pkg:deb/ubuntu/libwebp-dev?distro=jammy < 1.2.2-2ubuntu0.22.04.2
pkg:deb/ubuntu/libwebp-dev?distro=focal < 0.6.1-2ubuntu0.20.04.3
ID
USN-6369-1
Severity
high
Severity from
CVE-2023-4863
URL
https://ubuntu.com/security/notices/USN-6369-1
Published
2023-09-14T12:10:08
(12 months ago)
Modified
2023-09-14T12:10:08
(12 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/webp?distro=lunar ubuntu webp < 1.2.4-0.1ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/webp?distro=jammy ubuntu webp < 1.2.2-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/webp?distro=focal ubuntu webp < 0.6.1-2ubuntu0.20.04.3 focal
Affected pkg:deb/ubuntu/libwebpmux3?distro=lunar ubuntu libwebpmux3 < 1.2.4-0.1ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/libwebpmux3?distro=jammy ubuntu libwebpmux3 < 1.2.2-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libwebpmux3?distro=focal ubuntu libwebpmux3 < 0.6.1-2ubuntu0.20.04.3 focal
Affected pkg:deb/ubuntu/libwebpdemux2?distro=lunar ubuntu libwebpdemux2 < 1.2.4-0.1ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/libwebpdemux2?distro=jammy ubuntu libwebpdemux2 < 1.2.2-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libwebpdemux2?distro=focal ubuntu libwebpdemux2 < 0.6.1-2ubuntu0.20.04.3 focal
Affected pkg:deb/ubuntu/libwebp7?distro=lunar ubuntu libwebp7 < 1.2.4-0.1ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/libwebp7?distro=jammy ubuntu libwebp7 < 1.2.2-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libwebp6?distro=focal ubuntu libwebp6 < 0.6.1-2ubuntu0.20.04.3 focal
Affected pkg:deb/ubuntu/libwebp-dev?distro=lunar ubuntu libwebp-dev < 1.2.4-0.1ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/libwebp-dev?distro=jammy ubuntu libwebp-dev < 1.2.2-2ubuntu0.22.04.2 jammy
Affected pkg:deb/ubuntu/libwebp-dev?distro=focal ubuntu libwebp-dev < 0.6.1-2ubuntu0.20.04.3 focal
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...