A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1956853 | issue tracking third party advisory patch |
https://lists.debian.org/debian-lts-announce/2021/06/msg00005.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2021/06/msg00006.html | third party advisory mailing list |
https://www.debian.org/security/2021/dsa-4930 | third party advisory vendor advisory |
https://support.apple.com/kb/HT212601 | not applicable |
http://seclists.org/fulldisclosure/2021/Jul/54 | third party advisory mailing list |
https://security.netapp.com/advisory/ntap-20211104-0004/ | third party advisory |