CVE-2020-36330 is an out-of-bounds read vulnerability in libwebp versions prior to 1.0.1, impacting products from Apple, Debian, NetApp, Red Hat, and webmproject. This critical vulnerability (CVSS 9.1) can be exploited remotely with low complexity, posing a significant risk to data confidentiality and service availability. While no public exploit code or active exploitation has been confirmed, it has garnered some community discussion and media coverage, including a mention in a Threatpost article regarding Apple updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.1CPE matchmatch criteria | cpe:2.3:a:webmproject:libwebp:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
May 11, 2021libwebp: out-of-bounds read in ChunkVerifyAndAssign() in mux/muxread.c
Feb 25, 2020