2023-09-09 02:00:35 +00:00
{
2023-09-12 15:00:36 +00:00
"data_version" : "4.0" ,
2023-09-09 02:00:35 +00:00
"data_type" : "CVE" ,
"data_format" : "MITRE" ,
"CVE_data_meta" : {
"ID" : "CVE-2023-4863" ,
2023-09-12 15:00:36 +00:00
"ASSIGNER" : "chrome-cve-admin@google.com" ,
"STATE" : "PUBLIC"
2023-09-09 02:00:35 +00:00
} ,
"description" : {
"description_data" : [
{
"lang" : "eng" ,
2023-09-27 20:00:31 +00:00
"value" : "Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)"
2023-09-12 15:00:36 +00:00
}
]
} ,
"problemtype" : {
"problemtype_data" : [
{
"description" : [
{
"lang" : "eng" ,
"value" : "Heap buffer overflow"
}
]
}
]
} ,
"affects" : {
"vendor" : {
"vendor_data" : [
{
"vendor_name" : "Google" ,
"product" : {
"product_data" : [
{
"product_name" : "Chrome" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
"version_name" : "116.0.5845.187" ,
"version_value" : "116.0.5845.187"
}
]
}
2023-09-28 18:00:34 +00:00
} ,
{
"product_name" : "libwebp" ,
"version" : {
"version_data" : [
{
"version_affected" : "<" ,
2023-11-07 00:00:35 +00:00
"version_name" : "1.3.2" ,
"version_value" : "1.3.2"
2023-09-28 18:00:34 +00:00
}
]
}
2023-09-12 15:00:36 +00:00
}
]
}
}
]
}
} ,
"references" : {
"reference_data" : [
{
"url" : "https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html" ,
"refsource" : "MISC" ,
"name" : "https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html"
} ,
{
"url" : "https://crbug.com/1479274" ,
"refsource" : "MISC" ,
"name" : "https://crbug.com/1479274"
2023-09-13 17:00:33 +00:00
} ,
{
"url" : "https://en.bandisoft.com/honeyview/history/" ,
"refsource" : "MISC" ,
"name" : "https://en.bandisoft.com/honeyview/history/"
} ,
{
"url" : "https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/" ,
"refsource" : "MISC" ,
"name" : "https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/"
} ,
{
"url" : "https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/" ,
"refsource" : "MISC" ,
"name" : "https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/"
} ,
{
"url" : "https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a" ,
"refsource" : "MISC" ,
"name" : "https://github.com/webmproject/libwebp/commit/902bc9190331343b2017211debcec8d2ab87e17a"
} ,
{
"url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863" ,
"refsource" : "MISC" ,
"name" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863"
} ,
{
"url" : "https://security-tracker.debian.org/tracker/CVE-2023-4863" ,
"refsource" : "MISC" ,
"name" : "https://security-tracker.debian.org/tracker/CVE-2023-4863"
} ,
{
"url" : "https://bugzilla.suse.com/show_bug.cgi?id=1215231" ,
"refsource" : "MISC" ,
"name" : "https://bugzilla.suse.com/show_bug.cgi?id=1215231"
} ,
{
"url" : "https://news.ycombinator.com/item?id=37478403" ,
"refsource" : "MISC" ,
"name" : "https://news.ycombinator.com/item?id=37478403"
} ,
{
"url" : "https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/" ,
"refsource" : "MISC" ,
"name" : "https://www.bleepingcomputer.com/news/google/google-fixes-another-chrome-zero-day-bug-exploited-in-attacks/"
2023-09-14 21:00:34 +00:00
} ,
{
"url" : "https://www.debian.org/security/2023/dsa-5496" ,
"refsource" : "MISC" ,
"name" : "https://www.debian.org/security/2023/dsa-5496"
} ,
{
"url" : "https://www.debian.org/security/2023/dsa-5497" ,
"refsource" : "MISC" ,
"name" : "https://www.debian.org/security/2023/dsa-5497"
2023-09-15 04:00:33 +00:00
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX/" ,
"refsource" : "MISC" ,
"name" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OZDGWWMJREPAGKWCJKSCM4WYLANSKIFX/"
2023-09-15 22:00:34 +00:00
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645/" ,
"refsource" : "MISC" ,
"name" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FYYKLG6CRGEDTNRBSU26EEWAO6D6U645/"
2023-09-16 04:00:37 +00:00
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX/" ,
"refsource" : "MISC" ,
"name" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PYZV7TMKF4QHZ54SFJX54BDN52VHGGCX/"
2023-09-16 11:00:34 +00:00
} ,
{
"url" : "https://lists.debian.org/debian-lts-announce/2023/09/msg00015.html" ,
"refsource" : "MISC" ,
"name" : "https://lists.debian.org/debian-lts-announce/2023/09/msg00015.html"
2023-09-17 03:00:32 +00:00
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB/" ,
"refsource" : "MISC" ,
"name" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB/"
2023-09-17 09:00:34 +00:00
} ,
{
"url" : "https://www.debian.org/security/2023/dsa-5498" ,
"refsource" : "MISC" ,
"name" : "https://www.debian.org/security/2023/dsa-5498"
} ,
{
"url" : "https://security.gentoo.org/glsa/202309-05" ,
"refsource" : "MISC" ,
"name" : "https://security.gentoo.org/glsa/202309-05"
2023-09-17 12:00:33 +00:00
} ,
{
"url" : "https://lists.debian.org/debian-lts-announce/2023/09/msg00016.html" ,
"refsource" : "MISC" ,
"name" : "https://lists.debian.org/debian-lts-announce/2023/09/msg00016.html"
2023-09-18 04:00:37 +00:00
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/" ,
"refsource" : "MISC" ,
"name" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/"
2023-09-18 09:00:33 +00:00
} ,
{
"url" : "https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/" ,
"refsource" : "MISC" ,
"name" : "https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/"
} ,
{
"url" : "https://github.com/webmproject/libwebp/releases/tag/v1.3.2" ,
"refsource" : "MISC" ,
"name" : "https://github.com/webmproject/libwebp/releases/tag/v1.3.2"
2023-09-18 14:00:34 +00:00
} ,
{
"url" : "https://lists.debian.org/debian-lts-announce/2023/09/msg00017.html" ,
"refsource" : "MISC" ,
"name" : "https://lists.debian.org/debian-lts-announce/2023/09/msg00017.html"
2023-09-21 03:00:33 +00:00
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/" ,
"refsource" : "MISC" ,
"name" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/"
2023-09-22 00:00:32 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/21/4" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/21/4"
2023-09-22 04:00:33 +00:00
} ,
{
"url" : "https://blog.isosceles.com/the-webp-0day/" ,
"refsource" : "MISC" ,
"name" : "https://blog.isosceles.com/the-webp-0day/"
2023-09-22 09:00:32 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/22/1" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/22/1"
2023-09-22 15:00:33 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/22/3" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/22/3"
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/22/4" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/22/4"
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/22/5" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/22/5"
2023-09-22 18:00:33 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/22/8" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/22/8"
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/22/7" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/22/7"
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/22/6" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/22/6"
2023-09-27 14:59:13 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/26/1" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/26/1"
2023-09-27 20:00:31 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/26/7" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/26/7"
2023-09-28 12:00:33 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/28/1" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/28/1"
2023-09-28 15:00:34 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/28/2" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/28/2"
2023-09-28 18:00:34 +00:00
} ,
{
"url" : "http://www.openwall.com/lists/oss-security/2023/09/28/4" ,
"refsource" : "MISC" ,
"name" : "http://www.openwall.com/lists/oss-security/2023/09/28/4"
2023-09-29 22:00:32 +00:00
} ,
{
"url" : "https://security.netapp.com/advisory/ntap-20230929-0011/" ,
"refsource" : "MISC" ,
"name" : "https://security.netapp.com/advisory/ntap-20230929-0011/"
2023-10-02 02:00:34 +00:00
} ,
{
"url" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/" ,
"refsource" : "MISC" ,
"name" : "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/"
2023-10-27 18:00:31 +00:00
} ,
{
"url" : "https://sethmlarson.dev/security-developer-in-residence-weekly-report-16" ,
"refsource" : "MISC" ,
"name" : "https://sethmlarson.dev/security-developer-in-residence-weekly-report-16"
2023-10-28 19:00:35 +00:00
} ,
{
"url" : "https://www.bentley.com/advisories/be-2023-0001/" ,
"refsource" : "MISC" ,
"name" : "https://www.bentley.com/advisories/be-2023-0001/"
2023-09-09 02:00:35 +00:00
}
]
}
}