A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1956856 | patch third party advisory issue tracking |
https://lists.debian.org/debian-lts-announce/2021/06/msg00005.html | third party advisory mailing list |
https://lists.debian.org/debian-lts-announce/2021/06/msg00006.html | third party advisory mailing list |
https://www.debian.org/security/2021/dsa-4930 | vendor advisory mailing list third party advisory |
https://support.apple.com/kb/HT212601 | third party advisory |
http://seclists.org/fulldisclosure/2021/Jul/54 | third party advisory mailing list |
https://security.netapp.com/advisory/ntap-20211112-0001/ | third party advisory |