libwebp: Heap buffer overflow in WebP Codec
Published Sep 12, 2023 ·Due Oct 4, 2023
9.6
CRITICALCVSS 3.1
EPSS 99.98%
Description
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Affected products
-
- Version 116.0.5845.187StatusaffectedConstraints<116.0.5845.187
- Version
-
- Version 1.3.2StatusaffectedConstraints<1.3.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 2
- 37
- 38
- 39
Configuration 3
- 10.0
- 11.0
- 12.0
Configuration 4
- < 102.15.1
- < 117.0.1
- ≥ 115.1.0 · < 115.2.1
- < 102.15.1
- ≥ 115.0 · < 115.2.2
Configuration 5
- < 116.0.1938.81
- < 1.6.00.26463
- < 1.6.00.26474
- < 1.0.62681.0
Configuration 6
- < 1.3.2
Configuration 7
- n/a
Configuration 8
- < 2023.2
No data.
Red Hat Enterprise Linux 7
firefox-0:102.15.1-1.el7_9
Fixed · RHSA-2023:5197
Red Hat Enterprise Linux 7
thunderbird-0:102.15.1-1.el7_9
Fixed · RHSA-2023:5191
Red Hat Enterprise Linux 8
firefox-0:102.15.1-1.el8_8
Fixed · RHSA-2023:5184
Red Hat Enterprise Linux 8
libwebp-0:1.0.0-8.el8_8.1
Fixed · RHSA-2023:5309
Red Hat Enterprise Linux 8
thunderbird-0:102.15.1-1.el8_8
Fixed · RHSA-2023:5201
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
firefox-0:102.15.1-1.el8_1
Fixed · RHSA-2023:5183
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
libwebp-0:1.0.0-5.2.el8_1.1
Fixed · RHSA-2023:5236
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
thunderbird-0:102.15.1-1.el8_1
Fixed · RHSA-2023:5188
Red Hat Enterprise Linux 8.2 Advanced Update Support
firefox-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5187
Red Hat Enterprise Linux 8.2 Advanced Update Support
libwebp-0:1.0.0-7.el8_2.1
Fixed · RHSA-2023:5190
Red Hat Enterprise Linux 8.2 Advanced Update Support
thunderbird-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5186
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
firefox-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5187
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
libwebp-0:1.0.0-7.el8_2.1
Fixed · RHSA-2023:5190
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
thunderbird-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5186
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
firefox-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5187
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
libwebp-0:1.0.0-7.el8_2.1
Fixed · RHSA-2023:5190
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
thunderbird-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5186
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
firefox-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5192
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
libwebp-0:1.0.0-7.el8_4.1
Fixed · RHSA-2023:5222
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
thunderbird-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5185
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
firefox-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5192
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
libwebp-0:1.0.0-7.el8_4.1
Fixed · RHSA-2023:5222
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
thunderbird-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5185
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
firefox-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5192
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
libwebp-0:1.0.0-7.el8_4.1
Fixed · RHSA-2023:5222
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
thunderbird-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5185
Red Hat Enterprise Linux 8.6 Extended Update Support
firefox-0:102.15.1-1.el8_6
Fixed · RHSA-2023:5198
Red Hat Enterprise Linux 8.6 Extended Update Support
libwebp-0:1.0.0-7.el8_6.1
Fixed · RHSA-2023:5189
Red Hat Enterprise Linux 8.6 Extended Update Support
thunderbird-0:102.15.1-1.el8_6
Fixed · RHSA-2023:5202
Red Hat Enterprise Linux 9
firefox-0:102.15.1-1.el9_2
Fixed · RHSA-2023:5200
Red Hat Enterprise Linux 9
libwebp-0:1.2.0-7.el9_2
Fixed · RHSA-2023:5214
Red Hat Enterprise Linux 9
rhel9/firefox-flatpak:flatpak-9020020231006113910.2
Fixed · RHBA-2023:5988
Red Hat Enterprise Linux 9
rhel9/thunderbird-flatpak:flatpak-9020020231006114109.1
Fixed · RHBA-2023:6004
Red Hat Enterprise Linux 9
thunderbird-0:102.15.1-1.el9_2
Fixed · RHSA-2023:5224
Red Hat Enterprise Linux 9.0 Extended Update Support
firefox-0:102.15.1-1.el9_0
Fixed · RHSA-2023:5205
Red Hat Enterprise Linux 9.0 Extended Update Support
libwebp-0:1.2.0-6.el9_0
Fixed · RHSA-2023:5204
Red Hat Enterprise Linux 9.0 Extended Update Support
thunderbird-0:102.15.1-1.el9_0
Fixed · RHSA-2023:5223
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 7
libwebp
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | firefox-0:102.15.1-1.el7_9 | Fixed | RHSA-2023:5197 |
| Red Hat Enterprise Linux 7 | thunderbird-0:102.15.1-1.el7_9 | Fixed | RHSA-2023:5191 |
| Red Hat Enterprise Linux 8 | firefox-0:102.15.1-1.el8_8 | Fixed | RHSA-2023:5184 |
| Red Hat Enterprise Linux 8 | libwebp-0:1.0.0-8.el8_8.1 | Fixed | RHSA-2023:5309 |
| Red Hat Enterprise Linux 8 | thunderbird-0:102.15.1-1.el8_8 | Fixed | RHSA-2023:5201 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | firefox-0:102.15.1-1.el8_1 | Fixed | RHSA-2023:5183 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | libwebp-0:1.0.0-5.2.el8_1.1 | Fixed | RHSA-2023:5236 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | thunderbird-0:102.15.1-1.el8_1 | Fixed | RHSA-2023:5188 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | firefox-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5187 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | libwebp-0:1.0.0-7.el8_2.1 | Fixed | RHSA-2023:5190 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | thunderbird-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5186 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | firefox-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5187 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | libwebp-0:1.0.0-7.el8_2.1 | Fixed | RHSA-2023:5190 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | thunderbird-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5186 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | firefox-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5187 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | libwebp-0:1.0.0-7.el8_2.1 | Fixed | RHSA-2023:5190 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | thunderbird-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5186 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | firefox-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5192 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libwebp-0:1.0.0-7.el8_4.1 | Fixed | RHSA-2023:5222 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5185 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | firefox-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5192 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | libwebp-0:1.0.0-7.el8_4.1 | Fixed | RHSA-2023:5222 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | thunderbird-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5185 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | firefox-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5192 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | libwebp-0:1.0.0-7.el8_4.1 | Fixed | RHSA-2023:5222 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | thunderbird-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5185 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | firefox-0:102.15.1-1.el8_6 | Fixed | RHSA-2023:5198 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | libwebp-0:1.0.0-7.el8_6.1 | Fixed | RHSA-2023:5189 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | thunderbird-0:102.15.1-1.el8_6 | Fixed | RHSA-2023:5202 |
| Red Hat Enterprise Linux 9 | firefox-0:102.15.1-1.el9_2 | Fixed | RHSA-2023:5200 |
| Red Hat Enterprise Linux 9 | libwebp-0:1.2.0-7.el9_2 | Fixed | RHSA-2023:5214 |
| Red Hat Enterprise Linux 9 | rhel9/firefox-flatpak:flatpak-9020020231006113910.2 | Fixed | RHBA-2023:5988 |
| Red Hat Enterprise Linux 9 | rhel9/thunderbird-flatpak:flatpak-9020020231006114109.1 | Fixed | RHBA-2023:6004 |
| Red Hat Enterprise Linux 9 | thunderbird-0:102.15.1-1.el9_2 | Fixed | RHSA-2023:5224 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | firefox-0:102.15.1-1.el9_0 | Fixed | RHSA-2023:5205 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | libwebp-0:1.2.0-6.el9_0 | Fixed | RHSA-2023:5204 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | thunderbird-0:102.15.1-1.el9_0 | Fixed | RHSA-2023:5223 |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libwebp | Not affected | n/a |
magick.net-q8-anycpu
NuGet
Introduced 0 Fixed 13.3.0magick.net-q8-x64
NuGet
Introduced 0 Fixed 13.3.0libwebp-sys
crates.io
Introduced 0 Fixed 0.9.3electron
npm
Introduced 22.0.0 Fixed 22.3.24electron
npm
Introduced 24.0.0 Fixed 24.8.3electron
npm
Introduced 25.0.0 Fixed 25.8.1electron
npm
Introduced 26.0.0 Fixed 26.2.1electron
npm
Introduced 27.0.0-beta.1 Fixed 27.0.0-beta.2SkiaSharp
NuGet
Introduced 2.0.0 Fixed 2.88.6github.com/chai2010/webp
Go
Introduced 1.1.2 Fixed 1.4.0github.com/chai2010/webp
Go
Introduced 0 Fixed 0.0.0-20250406010349-76805d5a8860github.com/chai2010/webp
Go
Introduced 0.0.0 Fixed 1.1.2-0.20250406010349-76805d5a8860webp
crates.io
Introduced 0 Fixed 0.2.6magick.net-q16-anycpu
NuGet
Introduced 0 Fixed 13.3.0magick.net-q16-x64
NuGet
Introduced 0 Fixed 13.3.0magick.net-q8-openmp-x64
NuGet
Introduced 0 Fixed 13.3.0libwebp-sys2
crates.io
Introduced 0 Fixed 0.1.8pillow
PyPI
Introduced 0 Fixed 10.0.1magick.net-q16-hdri-anycpu
NuGet
Introduced 0 Fixed 13.3.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| NuGet | magick.net-q8-anycpu | 0 | 13.3.0 |
| NuGet | magick.net-q8-x64 | 0 | 13.3.0 |
| crates.io | libwebp-sys | 0 | 0.9.3 |
| npm | electron | 22.0.0 | 22.3.24 |
| npm | electron | 24.0.0 | 24.8.3 |
| npm | electron | 25.0.0 | 25.8.1 |
| npm | electron | 26.0.0 | 26.2.1 |
| npm | electron | 27.0.0-beta.1 | 27.0.0-beta.2 |
| NuGet | SkiaSharp | 2.0.0 | 2.88.6 |
| Go | github.com/chai2010/webp | 1.1.2 | 1.4.0 |
| Go | github.com/chai2010/webp | 0 | 0.0.0-20250406010349-76805d5a8860 |
| Go | github.com/chai2010/webp | 0.0.0 | 1.1.2-0.20250406010349-76805d5a8860 |
| crates.io | webp | 0 | 0.2.6 |
| NuGet | magick.net-q16-anycpu | 0 | 13.3.0 |
| NuGet | magick.net-q16-x64 | 0 | 13.3.0 |
| NuGet | magick.net-q8-openmp-x64 | 0 | 13.3.0 |
| crates.io | libwebp-sys2 | 0 | 0.1.8 |
| PyPI | pillow | 0 | 10.0.1 |
| NuGet | magick.net-q16-hdri-anycpu | 0 | 13.3.0 |
Remediation
Red Hat statement
This security issue has been classified as having an Important security impact. Desktop users are at a high risk of exploitation of this flaw with very minimal interaction. It may compromise the confidentiality, integrity, or availability of resources. Customers using this application, which does server-side image processing by linking to the libwebp library, are also potentially impacted by this flaw and are advised to update to the fixed versions of the package.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (70)
- http://www.openwall.com/lists/oss-security/2023/09/21/4 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/22/1 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/22/3 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/22/4 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/22/5 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/22/6 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/22/7 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/22/8 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/26/1 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/26/7 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/28/1 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/28/2 Mailing List
- http://www.openwall.com/lists/oss-security/2023/09/28/4 Mailing List
- https://access.redhat.com/security/cve/CVE-2023-4863 Vendor Advisory
- https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway Third Party Advisory
- https://blog.isosceles.com/the-webp-0day ExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2238431 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1215231 Issue TrackingThird Party Advisory
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html Vendor Advisory
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html
- https://crbug.com/1479274 Issue TrackingVendor Advisory
- https://en.bandisoft.com/honeyview/history Release Notes
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2533 Advisory
- https://github.com/ImageMagick/ImageMagick/discussions/6664
- https://github.com/advisories/GHSA-j7hp-h8jx-5ppr Advisory
- https://github.com/dlemstra/Magick.NET/releases/tag/13.3.0
- https://github.com/electron/electron/pull/39823
- https://github.com/electron/electron/pull/39825
- https://github.com/electron/electron/pull/39826
- https://github.com/electron/electron/pull/39827
- https://github.com/electron/electron/pull/39828
- https://github.com/jaredforth/webp/commit/9d4c56e63abecc777df71c702503c3eaabd7dcbc
- https://github.com/jaredforth/webp/pull/30
- https://github.com/python-pillow/Pillow/pull/7395
- https://github.com/qnighy/libwebp-sys2-rs/commit/4560c473a76ec8bd8c650f19ddf9d7a44f719f8b
- https://github.com/qnighy/libwebp-sys2-rs/pull/21
- https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a Patch
- https://github.com/webmproject/libwebp/releases/tag/v1.3.2 Release Notes
- https://lists.debian.org/debian-lts-announce/2023/09/msg00015.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00016.html Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/09/msg00017.html Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645 Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3 Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I Mailing List
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863 PatchThird Party Advisory
- https://news.ycombinator.com/item?id=37478403 ExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863
- https://pillow.readthedocs.io/en/stable/releasenotes/10.0.1.html#security
- https://rustsec.org/advisories/RUSTSEC-2023-0060.html
- https://rustsec.org/advisories/RUSTSEC-2023-0061.html
- https://security-tracker.debian.org/tracker/CVE-2023-4863 Issue TrackingThird Party Advisory
- https://security.gentoo.org/glsa/202309-05 Third Party Advisory
- https://security.gentoo.org/glsa/202401-10 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20230929-0011 Third Party Advisory
- https://sethmlarson.dev/security-developer-in-residence-weekly-report-16 Exploit
- https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863 ExploitThird Party Advisory
- https://www.bentley.com/advisories/be-2023-0001 Third Party Advisory
- https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-4863 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2023-4863
- https://www.debian.org/security/2023/dsa-5496 Mailing List
- https://www.debian.org/security/2023/dsa-5497 Mailing List
- https://www.debian.org/security/2023/dsa-5498 Mailing ListThird Party Advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-40 Third Party Advisory
- https://www.vicarius.io/vsociety/posts/zero-day-webp-vulnerability-cve-2023-4863 ExploitThird Party Advisory
Change history (0)
No recorded changes yet.