E23-1pbj1
CVSS:
8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2023
Description
This strike exploits a buffer overflow vulnerability in Google libwebp.
The vulnerability is due to a statically size heap buffer used to hold Huffman tables constructed from data within WebP image files.
A remote attacker could exploit this vulnerability by enticing a target user to open a crafted WebP file containing 5 Huffman tables whose sum of entries is larger than the precalculated buffer size.
Successful exploitation could result in execution of arbitrary code in the context of the vulnerable application opening the WebP file.
CVE
References
https://blog.isosceles.com/the-webp-0day/