Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 9 DLA-2677-1 Moderate: Libwebp Buffer Overflow Threats

debian lts
Calendar Grey June 6, 2021
Dist Debian Esm H88
Enhance libwebp on Debian 9 to address numerous vulnerabilities such as buffer overflows and risks to data privacy.
Multiple security issues have been discovered in libwebp CVE-2018-25009

Summary

CVE-2018-25009

An out-of-bounds read was found in function WebPMuxCreateInternal.
The highest threat from this vulnerability is to data confidentiality
and to the service availability.

CVE-2018-25010

An out-of-bounds read was found in function ApplyFilter.
The highest threat from this vulnerability is to data confidentiality
and to the service availability.

CVE-2018-25011

A heap-based buffer overflow was found in PutLE16().
The highest threat from this vulnerability is to data confidentiality
and integrity as well as system availability.

CVE-2018-25012

An out-of-bounds read was found in function WebPMuxCreateInternal.
The highest threat from this vulnerability is to data confidentiality
and to the service availability.

CVE-2018-25013

An out-of-bounds read was found in function ShiftBytes.
The highest threat from this vulnerability is to data confidentiality
and to the service availability.

CVE-2018-25014

Read the Full Advisory


Package: libwebp
Version: 0.5.2-1+deb9u1
CVE ID: CVE-2018-25009 CVE-2018-25010 CVE-2018-25011 CVE-2018-25012

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here