Google Libwebp Heap Buffer Overflow

Strike ID:
E23-1pbj1
CVSS:
8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
False Positive:
f
Variants:
1
Year:
2023

Description

This strike exploits a buffer overflow vulnerability in Google libwebp. The vulnerability is due to a statically size heap buffer used to hold Huffman tables constructed from data within WebP image files. A remote attacker could exploit this vulnerability by enticing a target user to open a crafted WebP file containing 5 Huffman tables whose sum of entries is larger than the precalculated buffer size. Successful exploitation could result in execution of arbitrary code in the context of the vulnerable application opening the WebP file.

CVE

References