CVE-2023-5217

Source
https://cve.org/CVERecord?id=CVE-2023-5217
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5217.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-5217
Aliases
Downstream
CGA (2)
DEBIAN (1)
ECHO (1)
JLSEC (1)
MGASA (3)
OESA (2)
openSUSE (17)
RHSA (23)
RLSA (3)
SUSE (7)
UBUNTU (1)
Related
Published
2023-09-28T15:23:18Z
Modified
2026-08-12T14:51:51Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Database specific
{
    "cna_assigner":  "Chrome",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/5xxx/CVE-2023-5217.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "117.0.5938.132"
                },
                {
                    "last_affected":  "117.0.5938.132"
                }
            ],
            "source":  "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/webmproject/libvpx

Affected ranges

Type
GIT
Repo
https://github.com/webmproject/libvpx
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:webmproject:libvpx:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.13.1"
        }
    ],
    "source":  [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.13.1
v0.*
v0.9.0
v0.9.1
v0.9.6
v0.9.7
v0.9.7-p1
v1.*
v1.0.0
v1.10.0-rc1
v1.13.0
v1.13.0-rc1
v1.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-5217.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "100230110426315063526584035075349816268",
            "length":  828
        },
        "id":  "CVE-2023-5217-59c4ee72",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282",
        "target":  {
            "file":  "test/encode_api_test.cc",
            "function":  "TEST"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "330207852396136827555187902995997508991",
                "136729999502473988878370435018177723713",
                "15678369136114235740638393954350936456",
                "29923588737913573680652580060977133403",
                "37773578129138277403789668865252074553",
                "208095115678472981879396413634191585616",
                "208615308191935464082942480319992654085",
                "6770653278206996996157363816394479362",
                "300357361493662169961043031214313606186",
                "216511662522186585972998914279732097668"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2023-5217-b975f3f7",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282",
        "target":  {
            "file":  "test/encode_api_test.cc"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "145482218640286121211368997722597947029",
                "168502398490642422058993771546900085627",
                "4517982599115396846171772755713147428"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2023-5217-d8e47c27",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590",
        "target":  {
            "file":  "vp8/encoder/onyx_if.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "174559640541706553597192381471309499032",
            "length":  421
        },
        "id":  "CVE-2023-5217-ddc6739b",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282",
        "target":  {
            "file":  "test/encode_api_test.cc",
            "function":  "InitCodec"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "9318311977028663908885622115267581070",
            "length":  8188
        },
        "id":  "CVE-2023-5217-eb8089c4",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590",
        "target":  {
            "file":  "vp8/encoder/onyx_if.c",
            "function":  "vp8_change_config"
        }
    }
]
vanir_signatures_modified
"2026-08-12T14:51:51Z"