Critical vulnerabilities in media libraries exploited in the wild: everything you need to know
ID: 62211936-aaaf-523a-aaca-f78bfe8bfe7c
STIX ID: report--62211936-aaaf-523a-aaca-f78bfe8bfe7c
Feed Name: Wiz Blog
This advisory describes two recently disclosed and reportedly in-the-wild exploited codec vulnerabilities: CVE-2023-4863 (a critical heap out-of-bounds write in libwebp affecting WebP image decoding used by browsers and many client apps) and CVE-2023-5217 (a high-severity heap overflow in libvpx affecting VP8/VP9 video decoding). The report provides technical details of the root-cause bugs, lists affected library versions and dependent products, notes limited public details about actual exploit campaigns, and recommends prioritizing patches for client applications and any servers or build environments that process images or video.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
