Image I/O & WebP/libwebp Zero-Day Vulnerabilities
ID: d51f4a47-4d79-5eef-a9ab-2e9d61d71a63
STIX ID: report--d51f4a47-4d79-5eef-a9ab-2e9d61d71a63
Feed Name: Kudelski Security
This advisory details CVE-2023-4863, a heap-buffer-overflow in the libwebp WebP decoder that allows out-of-bounds writes from crafted lossless WebP files, potentially leading to denial-of-service or remote code execution. The flaw affects a wide range of applications and OS components (hundreds of products), has been associated with real-world exploitation in an iOS/spyware chain, and the report recommends patching, disabling WebP processing where feasible, and applying network/IDS mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
