by @Smartkeyss
14 Feb 2024

Zero Day WebP vulnerability (CVE-2023-4863)

by @Smartkeyss
14 Feb 2024

Zero Day WebP vulnerability (CVE-2023-4863)

CVEs

8.8 High Severity

OS

22.04.*
2.5.3-3.*
2.5.3-16.*
2.5.2-1.*
*.*
2.1.8.8.p3-1.1.*
10.10.*
3.0.23.*
12.4.*
3.0.18.*
Fedora
FedoraFedoraproject
41.0.1.0.*
40.0.0.0.*
*.*
3334.*
37.*
30.*
40.*
38.*
28.*
31.*

Apps

140.3.1.*
115.28.0.*
115.27.0.*
128.14.0.*
128.13.0.*
115.26.0.*
115.25.0.*
128.12.0.*
115.24.0.*
128.11.0.*
Firefox
FirefoxMozilla
148.0.2.*
115.33.0.*
148.0.0.0.*
115.32.1.*
147.0.4.*
147.0.3.*
148.0.2.0.*
140.7.1.*
147.0.2.*
147.0.1.0.*
149.0.3.0.*
140.8.1.0.*
140.8.1.*
148.0.1.*
149.0.2.0.*
149.0.1.0.*
140.8.0.0.*
148.0.0.0.*
148.0.5.0.*
140.7.2.*
Chrome
ChromeGoogle
148.0.7734.3.*
148.0.7734.2.*
148.0.7734.0.*
146.0.7680.80.*
148.0.7732.1.*
148.0.7733.0.*
148.0.7730.2.*
148.0.7732.0.*
148.0.7731.1.*
146.0.7680.75.*
Edge
EdgeMicrosoft
146.0.3856.62.*
146.0.3856.59.*
147.0.3912.0.*
147.0.3911.0.*
147.0.3901.1.*
146.0.3856.54.*
147.0.3910.0.*
147.0.3909.0.*
145.0.3800.99.*
147.0.3908.0.*
L
LibwebpWebmproject
*.*
0.5.1.*
1.2.2.RC1
1.2.2.-
1.2.2.RC2
1.2.3.-
1.2.3.RC1
1.2.1.RC2
1.2.1.-
1.2.0.-

Screenshots from the blog posts

images/clsev7h0q8f5t1hon57nu44i3.pngimages/clsev7h0q8f5t1hon57nu44i3.png
images/clsdn1n7o5jos1hon00qpd5mv.jpgimages/clsdn1n7o5jos1hon00qpd5mv.jpg
images/clsev8cob8f9a1hon6t6bbjjt.jpgimages/clsev8cob8f9a1hon6t6bbjjt.jpg

Summary

CVE-2023-4863 (CVSS score: 8.8), also known as the heap buffer overflow in Chrome libWebP, is a client-side vulnerability. This means that the end user of the affected application is at risk. The vulnerability arises from an exploitation involving the writing of more data to a dynamically allocated memory space (heap buffer) than it can hold, using crafted HTML. This vulnerability could lead to a crash or enable the exploiter to execute arbitrary code on the end user's system. 

Description

users/photos/clsevlral8gef1hon15grbvup.jpg

@Smartkeyss

63 posts

I am just curious 😊 I use simple words to explain complicated things. discord: @rxs_s

Total vcoins

0

Social media links

Comments (0)