CVE-2020-36328 is a critical heap-based buffer overflow vulnerability in libwebp versions prior to 1.0.1, specifically within the WebPDecodeRGBInto function due to an invalid buffer size check. This flaw impacts products from vendors like Apple, Debian, NetApp, Red Hat, and webmproject. With a CVSS score of 9.8 (CRITICAL), it poses a significant threat to data confidentiality, integrity, and system availability, allowing unauthenticated attackers to exploit it remotely with low complexity. Despite its severity, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA KEV, and community discussion and media coverage are minimal, suggesting limited active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.1CPE matchmatch criteria | cpe:2.3:a:webmproject:libwebp:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
May 11, 2021libwebp: heap-based buffer overflow in WebPDecode*Into functions
Feb 25, 2020