DSA-5497-1

Source
https://storage.googleapis.com/debian-osv/dsa-osv/DSA-5497-1.json
Published
2023-09-13T00:00:00Z
Modified
2023-09-14T07:18:03.431961Z
Details

A buffer overflow in parsing WebP images may result in the execution of arbitrary code.

For the stable distribution (bookworm), this problem has been fixed in version 1.2.4-0.2+deb12u1.

We recommend that you upgrade your libwebp packages.

For the detailed security status of libwebp please refer to its security tracker page at: \ https://security-tracker.debian.org/tracker/libwebp

References

Affected packages

Debian:12 / libwebp

Source Details

Package Name
libwebp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
1.2.4-0.2+deb12u1

Affected versions

1.*

1.2.4-0.2