DSA-5497-2

Source
https://storage.googleapis.com/debian-osv/dsa-osv/DSA-5497-2.json
Published
2023-09-13T00:00:00Z
Modified
2023-09-17T19:17:49.013077Z
Details

A buffer overflow in parsing WebP images may result in the execution of arbitrary code.

For the stable distribution (bookworm), this problem has been fixed in version 1.2.4-0.2+deb12u1.

We recommend that you upgrade your libwebp packages.

For the detailed security status of libwebp please refer to its security tracker page at: \ https://security-tracker.debian.org/tracker/libwebp

References

Affected packages

Debian:11 / libwebp

Source Details

Package Name
libwebp

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
0.6.1-2.1+deb11u2

Affected versions

0.*

0.6.1-2.1
0.6.1-2.1+deb11u1