CVE-2023-4863
HIGH8.8⚠ KEVEPSS 93.3%libwebp: OOB write in BuildHuffmanTable
Published: 9/12/2023Modified: 4/28/2026Added to CISA KEV: 9/13/2023
Description
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Affected packages (33)
- Alpine/libwebpfrom 0, < 1.2.2-r2
- crates.io/libwebp-sys>= 0.0.0-0, < 0.9.3
- crates.io/libwebp-sysfrom 0, < 0.9.3
- crates.io/libwebp-sys2from 0, < 0.1.8
- crates.io/libwebp-sys2>= 0.0.0-0, < 0.1.8
- crates.io/webpfrom 0, < 0.2.6
- Debian/chromiumfrom 0, < 117.0.5938.62-1
- Debian/firefox-esrfrom 0, < 102.15.1esr-1~deb11u1
- Debian/firefox-esrfrom 0, < 102.15.1esr-1~deb10u1
- Debian/firefox-esrfrom 0, < 102.15.1esr-1~deb11u1
- Debian/libwebpfrom 0, < 0.6.1-2.1+deb11u2
- Debian/libwebpfrom 0, < 1.2.4-0.2+deb12u1
- Debian/libwebpfrom 0, < 0.6.1-2.1+deb11u2
- Debian/libwebpfrom 0, < 0.6.1-2+deb10u3
- Debian/thunderbirdfrom 0, < 1:102.15.1-1~deb11u1
- Debian/thunderbirdfrom 0, < 1:102.15.1-1~deb10u1
- Debian/thunderbirdfrom 0, < 1:102.15.1-1~deb11u1
- Go/github.com/chai2010/webp>= 1.1.2, < 1.4.0
- npm/electron>= 22.0.0, < 22.3.24
- NuGet/magick.net-q16-anycpufrom 0, < 13.3.0
- NuGet/magick.net-q16-hdri-anycpufrom 0, < 13.3.0
- NuGet/magick.net-q16-x64from 0, < 13.3.0
- NuGet/magick.net-q8-anycpufrom 0, < 13.3.0
- NuGet/magick.net-q8-openmp-x64from 0, < 13.3.0
- NuGet/magick.net-q8-x64from 0, < 13.3.0
- NuGet/SkiaSharp>= 2.0.0, < 2.88.6
- PyPI/imagecodecsfrom 0, < 2023.9.18
- PyPI/opencv-contrib-pythonfrom 0, < 4.8.1.78
- PyPI/opencv-contrib-python-headlessfrom 0, < 4.8.1.78
- PyPI/opencv-pythonfrom 0, < 4.8.1.78
- PyPI/opencv-python-headlessfrom 0, < 4.8.1.78
- PyPI/pillowfrom 0, < 10.0.1
- PyPI/pillowfrom 0, < 10.0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
References (71)
- ADVISORYhttps://github.com/cgohlke/imagecodecs/blob/v2023.9.18/CHANGES.rst
- ADVISORYhttps://github.com/opencv/opencv/wiki/ChangeLog#version481
- ADVISORYhttps://github.com/python-pillow/Pillow/blob/main/CHANGES.rst#1001-2023-09-15
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-4863
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2023-5129
- ADVISORYhttps://security.alpinelinux.org/vuln/CVE-2023-4863
- PATCHhttps://crates.io/crates/libwebp-sys
- PATCHhttps://crates.io/crates/libwebp-sys2
- PATCHhttps://github.com/opencv/opencv/pull/24274
- PATCHhttps://github.com/webmproject/libwebp
- WEBhttps://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway
- WEBhttps://blog.isosceles.com/the-webp-0day
- WEBhttps://bugzilla.suse.com/show_bug.cgi?id=1215231
- WEBhttps://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html
- WEBhttps://crbug.com/1479274
- WEBhttps://en.bandisoft.com/honeyview/history
- WEBhttps://github.com/dlemstra/Magick.NET/releases/tag/13.3.0
- WEBhttps://github.com/electron/electron/pull/39823
- WEBhttps://github.com/electron/electron/pull/39825
- WEBhttps://github.com/electron/electron/pull/39826
- WEBhttps://github.com/electron/electron/pull/39827
- WEBhttps://github.com/electron/electron/pull/39828
- WEBhttps://github.com/ImageMagick/ImageMagick/discussions/6664
- WEBhttps://github.com/jaredforth/webp/commit/9d4c56e63abecc777df71c702503c3eaabd7dcbc
- WEBhttps://github.com/jaredforth/webp/pull/30
- WEBhttps://github.com/python-pillow/Pillow/pull/7395
- WEBhttps://github.com/qnighy/libwebp-sys2-rs/commit/4560c473a76ec8bd8c650f19ddf9d7a44f719f8b
- WEBhttps://github.com/qnighy/libwebp-sys2-rs/pull/21
- WEBhttps://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a
- WEBhttps://github.com/webmproject/libwebp/releases/tag/v1.3.2
- WEBhttps://lists.debian.org/debian-lts-announce/2023/09/msg00015.html
- WEBhttps://lists.debian.org/debian-lts-announce/2023/09/msg00016.html
- WEBhttps://lists.debian.org/debian-lts-announce/2023/09/msg00017.html
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB
- WEBhttps://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I
- WEBhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863
- WEBhttps://news.ycombinator.com/item?id=37478403
- WEBhttps://pillow.readthedocs.io/en/stable/releasenotes/10.0.1.html#security
- WEBhttps://rustsec.org/advisories/RUSTSEC-2023-0060.html
- WEBhttps://rustsec.org/advisories/RUSTSEC-2023-0061.html
- WEBhttps://security.gentoo.org/glsa/202309-05
- WEBhttps://security.gentoo.org/glsa/202401-10
- WEBhttps://security.netapp.com/advisory/ntap-20230929-0011
- WEBhttps://security-tracker.debian.org/tracker/CVE-2023-4863
- WEBhttps://sethmlarson.dev/security-developer-in-residence-weekly-report-16
- … 21 more