CVE-2020-36328

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:webmproject:libwebp:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

Configuration 4 (hide)

OR cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

Configuration 5 (hide)

OR cpe:2.3:o:apple:ipados:14.7:*:*:*:*:*:*:*
cpe:2.3:o:apple:iphone_os:14.7:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-05-21 17:15

Updated : 2024-02-28 18:28


NVD link : CVE-2020-36328

Mitre link : CVE-2020-36328

CVE.ORG link : CVE-2020-36328


JSON object : View

Products Affected

debian

  • debian_linux

webmproject

  • libwebp

redhat

  • enterprise_linux

apple

  • iphone_os
  • ipados

netapp

  • ontap_select_deploy_administration_utility
CWE
CWE-787

Out-of-bounds Write