libwebp: out-of-bounds write with a specially crafted WebP lossless file
Published Sep 25, 2023
No CVSS score
EPSS 0.04%
Description
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Duplicate of CVE-2023-4863.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 7
firefox-0:102.15.1-1.el7_9
Fixed · RHSA-2023:5197
Red Hat Enterprise Linux 7
thunderbird-0:102.15.1-1.el7_9
Fixed · RHSA-2023:5191
Red Hat Enterprise Linux 8
firefox-0:102.15.1-1.el8_8
Fixed · RHSA-2023:5184
Red Hat Enterprise Linux 8
libwebp-0:1.0.0-8.el8_8.1
Fixed · RHSA-2023:5309
Red Hat Enterprise Linux 8
thunderbird-0:102.15.1-1.el8_8
Fixed · RHSA-2023:5201
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
firefox-0:102.15.1-1.el8_1
Fixed · RHSA-2023:5183
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
libwebp-0:1.0.0-5.2.el8_1.1
Fixed · RHSA-2023:5236
Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions
thunderbird-0:102.15.1-1.el8_1
Fixed · RHSA-2023:5188
Red Hat Enterprise Linux 8.2 Advanced Update Support
firefox-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5187
Red Hat Enterprise Linux 8.2 Advanced Update Support
libwebp-0:1.0.0-7.el8_2.1
Fixed · RHSA-2023:5190
Red Hat Enterprise Linux 8.2 Advanced Update Support
thunderbird-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5186
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
firefox-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5187
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
libwebp-0:1.0.0-7.el8_2.1
Fixed · RHSA-2023:5190
Red Hat Enterprise Linux 8.2 Telecommunications Update Service
thunderbird-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5186
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
firefox-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5187
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
libwebp-0:1.0.0-7.el8_2.1
Fixed · RHSA-2023:5190
Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions
thunderbird-0:102.15.1-1.el8_2
Fixed · RHSA-2023:5186
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
firefox-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5192
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
thunderbird-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5185
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
firefox-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5192
Red Hat Enterprise Linux 8.4 Telecommunications Update Service
thunderbird-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5185
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
firefox-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5192
Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions
thunderbird-0:102.15.1-1.el8_4
Fixed · RHSA-2023:5185
Red Hat Enterprise Linux 8.6 Extended Update Support
firefox-0:102.15.1-1.el8_6
Fixed · RHSA-2023:5198
Red Hat Enterprise Linux 8.6 Extended Update Support
libwebp-0:1.0.0-7.el8_6.1
Fixed · RHSA-2023:5189
Red Hat Enterprise Linux 8.6 Extended Update Support
thunderbird-0:102.15.1-1.el8_6
Fixed · RHSA-2023:5202
Red Hat Enterprise Linux 9
firefox-0:102.15.1-1.el9_2
Fixed · RHSA-2023:5200
Red Hat Enterprise Linux 9
libwebp-0:1.2.0-7.el9_2
Fixed · RHSA-2023:5214
Red Hat Enterprise Linux 9
thunderbird-0:102.15.1-1.el9_2
Fixed · RHSA-2023:5224
Red Hat Enterprise Linux 9.0 Extended Update Support
firefox-0:102.15.1-1.el9_0
Fixed · RHSA-2023:5205
Red Hat Enterprise Linux 9.0 Extended Update Support
libwebp-0:1.2.0-6.el9_0
Fixed · RHSA-2023:5204
Red Hat Enterprise Linux 9.0 Extended Update Support
thunderbird-0:102.15.1-1.el9_0
Fixed · RHSA-2023:5223
Red Hat Enterprise Linux 6
firefox
Out of support scope
Red Hat Enterprise Linux 7
libwebp
Not affected
Red Hat Enterprise Linux 9
firefox:flatpak/firefox
Affected
Red Hat Enterprise Linux 9
thunderbird:flatpak/thunderbird
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | firefox-0:102.15.1-1.el7_9 | Fixed | RHSA-2023:5197 |
| Red Hat Enterprise Linux 7 | thunderbird-0:102.15.1-1.el7_9 | Fixed | RHSA-2023:5191 |
| Red Hat Enterprise Linux 8 | firefox-0:102.15.1-1.el8_8 | Fixed | RHSA-2023:5184 |
| Red Hat Enterprise Linux 8 | libwebp-0:1.0.0-8.el8_8.1 | Fixed | RHSA-2023:5309 |
| Red Hat Enterprise Linux 8 | thunderbird-0:102.15.1-1.el8_8 | Fixed | RHSA-2023:5201 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | firefox-0:102.15.1-1.el8_1 | Fixed | RHSA-2023:5183 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | libwebp-0:1.0.0-5.2.el8_1.1 | Fixed | RHSA-2023:5236 |
| Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions | thunderbird-0:102.15.1-1.el8_1 | Fixed | RHSA-2023:5188 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | firefox-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5187 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | libwebp-0:1.0.0-7.el8_2.1 | Fixed | RHSA-2023:5190 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | thunderbird-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5186 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | firefox-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5187 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | libwebp-0:1.0.0-7.el8_2.1 | Fixed | RHSA-2023:5190 |
| Red Hat Enterprise Linux 8.2 Telecommunications Update Service | thunderbird-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5186 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | firefox-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5187 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | libwebp-0:1.0.0-7.el8_2.1 | Fixed | RHSA-2023:5190 |
| Red Hat Enterprise Linux 8.2 Update Services for SAP Solutions | thunderbird-0:102.15.1-1.el8_2 | Fixed | RHSA-2023:5186 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | firefox-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5192 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | thunderbird-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5185 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | firefox-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5192 |
| Red Hat Enterprise Linux 8.4 Telecommunications Update Service | thunderbird-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5185 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | firefox-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5192 |
| Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions | thunderbird-0:102.15.1-1.el8_4 | Fixed | RHSA-2023:5185 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | firefox-0:102.15.1-1.el8_6 | Fixed | RHSA-2023:5198 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | libwebp-0:1.0.0-7.el8_6.1 | Fixed | RHSA-2023:5189 |
| Red Hat Enterprise Linux 8.6 Extended Update Support | thunderbird-0:102.15.1-1.el8_6 | Fixed | RHSA-2023:5202 |
| Red Hat Enterprise Linux 9 | firefox-0:102.15.1-1.el9_2 | Fixed | RHSA-2023:5200 |
| Red Hat Enterprise Linux 9 | libwebp-0:1.2.0-7.el9_2 | Fixed | RHSA-2023:5214 |
| Red Hat Enterprise Linux 9 | thunderbird-0:102.15.1-1.el9_2 | Fixed | RHSA-2023:5224 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | firefox-0:102.15.1-1.el9_0 | Fixed | RHSA-2023:5205 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | libwebp-0:1.2.0-6.el9_0 | Fixed | RHSA-2023:5204 |
| Red Hat Enterprise Linux 9.0 Extended Update Support | thunderbird-0:102.15.1-1.el9_0 | Fixed | RHSA-2023:5223 |
| Red Hat Enterprise Linux 6 | firefox | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | libwebp | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox:flatpak/firefox | Affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird:flatpak/thunderbird | Affected | n/a |
SkiaSharp
NuGet
Introduced 2.0.0 Fixed 2.88.6github.com/chai2010/webp
Go
Introduced 0.0.0 Fixed 1.1.2-0.20250406010349-76805d5a8860github.com/chai2010/webp
Go
Introduced 1.1.2 Fixed 1.4.0github.com/chai2010/webp
Go
Introduced 0 Fixed 0.0.0-20250406010349-76805d5a8860pillow
PyPI
Introduced 0 Fixed 10.0.1webp
crates.io
Introduced 0 Fixed 0.2.6magick.net-q8-anycpu
NuGet
Introduced 0 Fixed 13.3.0magick.net-q8-openmp-x64
NuGet
Introduced 0 Fixed 13.3.0magick.net-q8-x64
NuGet
Introduced 0 Fixed 13.3.0libwebp-sys2
crates.io
Introduced 0 Fixed 0.1.8electron
npm
Introduced 24.0.0 Fixed 24.8.3electron
npm
Introduced 25.0.0 Fixed 25.8.1electron
npm
Introduced 26.0.0 Fixed 26.2.1electron
npm
Introduced 27.0.0-beta.1 Fixed 27.0.0-beta.2electron
npm
Introduced 22.0.0 Fixed 22.3.24magick.net-q16-anycpu
NuGet
Introduced 0 Fixed 13.3.0magick.net-q16-hdri-anycpu
NuGet
Introduced 0 Fixed 13.3.0magick.net-q16-x64
NuGet
Introduced 0 Fixed 13.3.0libwebp-sys
crates.io
Introduced 0 Fixed 0.9.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| NuGet | SkiaSharp | 2.0.0 | 2.88.6 |
| Go | github.com/chai2010/webp | 0.0.0 | 1.1.2-0.20250406010349-76805d5a8860 |
| Go | github.com/chai2010/webp | 1.1.2 | 1.4.0 |
| Go | github.com/chai2010/webp | 0 | 0.0.0-20250406010349-76805d5a8860 |
| PyPI | pillow | 0 | 10.0.1 |
| crates.io | webp | 0 | 0.2.6 |
| NuGet | magick.net-q8-anycpu | 0 | 13.3.0 |
| NuGet | magick.net-q8-openmp-x64 | 0 | 13.3.0 |
| NuGet | magick.net-q8-x64 | 0 | 13.3.0 |
| crates.io | libwebp-sys2 | 0 | 0.1.8 |
| npm | electron | 24.0.0 | 24.8.3 |
| npm | electron | 25.0.0 | 25.8.1 |
| npm | electron | 26.0.0 | 26.2.1 |
| npm | electron | 27.0.0-beta.1 | 27.0.0-beta.2 |
| npm | electron | 22.0.0 | 22.3.24 |
| NuGet | magick.net-q16-anycpu | 0 | 13.3.0 |
| NuGet | magick.net-q16-hdri-anycpu | 0 | 13.3.0 |
| NuGet | magick.net-q16-x64 | 0 | 13.3.0 |
| crates.io | libwebp-sys | 0 | 0.9.3 |
Remediation
Red Hat statement
This flaw was found to be a duplicate of CVE-2023-4863. Please see https://access.redhat.com/security/cve/CVE-2023-4863 for information about affected products and security errata.
References (7)
- https://access.redhat.com/security/cve/CVE-2023-5129 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2240759 Issue Tracking
- https://chromium.googlesource.com/webm/libwebp/+/2af26267cdfcb63a88e5c74a85927a12d6ca1d76
- https://chromium.googlesource.com/webm/libwebp/+/902bc9190331343b2017211debcec8d2ab87e17a
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-57467 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-5129
- https://www.cve.org/CVERecord?id=CVE-2023-5129
Change history (0)
No recorded changes yet.