CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially...

Basic Information

CVE State
PUBLISHED
Reserved Date
September 27, 2023
Published Date
September 28, 2023
Last Updated
February 13, 2025
Vendor
Google
Product
Chrome, libvpx
Description
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS Scores

CVSS v3.1

8.8 - HIGH

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2023-10-02 00:00:00 UTC) Source

References

https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html https://crbug.com/1486441 http://www.openwall.com/lists/oss-security/2023/09/28/5 http://www.openwall.com/lists/oss-security/2023/09/28/6 http://www.openwall.com/lists/oss-security/2023/09/29/1 http://www.openwall.com/lists/oss-security/2023/09/29/2 http://www.openwall.com/lists/oss-security/2023/09/29/7 http://www.openwall.com/lists/oss-security/2023/09/29/9 https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/ https://security-tracker.debian.org/tracker/CVE-2023-5217 https://bugzilla.redhat.com/show_bug.cgi?id=2241191 https://stackdiary.com/google-discloses-a-webm-vp8-bug-tracked-as-cve-2023-5217/ https://www.openwall.com/lists/oss-security/2023/09/28/5 https://pastebin.com/TdkC4pDv https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590 https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282 https://github.com/webmproject/libvpx/tags http://www.openwall.com/lists/oss-security/2023/09/29/11 http://www.openwall.com/lists/oss-security/2023/09/29/12 http://www.openwall.com/lists/oss-security/2023/09/29/14 https://www.debian.org/security/2023/dsa-5510 https://www.debian.org/security/2023/dsa-5509 https://www.debian.org/security/2023/dsa-5508 http://www.openwall.com/lists/oss-security/2023/09/30/1 https://lists.debian.org/debian-lts-announce/2023/09/msg00038.html https://twitter.com/maddiestone/status/1707163313711497266 https://arstechnica.com/security/2023/09/new-0-day-in-chrome-and-firefox-is-likely-to-plague-other-software/ https://github.com/webmproject/libvpx/releases/tag/v1.13.1 http://www.openwall.com/lists/oss-security/2023/09/30/3 http://www.openwall.com/lists/oss-security/2023/09/30/2 http://www.openwall.com/lists/oss-security/2023/09/30/4 http://www.openwall.com/lists/oss-security/2023/09/30/5 https://lists.fedoraproject.org/archives/list/[email protected]/message/BCVSHVX2RFBU3RMCUFSATVQEJUFD4Q63/ http://www.openwall.com/lists/oss-security/2023/10/01/2 http://www.openwall.com/lists/oss-security/2023/10/01/1 http://www.openwall.com/lists/oss-security/2023/10/01/5 https://lists.debian.org/debian-lts-announce/2023/10/msg00001.html https://lists.fedoraproject.org/archives/list/[email protected]/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/ https://lists.fedoraproject.org/archives/list/[email protected]/message/55YVCZNAVY3Y5E4DWPWMX2SPKZ2E5SOV/ https://lists.fedoraproject.org/archives/list/[email protected]/message/4MFWDFJSSIFKWKNOCTQCFUNZWAXUCSS4/ https://lists.fedoraproject.org/archives/list/[email protected]/message/CWEJYS5NC7KVFYU3OAMPKQDYN6JQGVK6/ http://www.openwall.com/lists/oss-security/2023/10/02/6 http://www.openwall.com/lists/oss-security/2023/10/03/11 https://security.gentoo.org/glsa/202310-04 https://support.apple.com/kb/HT213961 https://lists.fedoraproject.org/archives/list/[email protected]/message/AY642Z6JZODQJE7Z62CFREVUHEGCXGPD/ http://seclists.org/fulldisclosure/2023/Oct/12 https://lists.debian.org/debian-lts-announce/2023/10/msg00015.html https://support.apple.com/kb/HT213972 http://seclists.org/fulldisclosure/2023/Oct/16 https://lists.fedoraproject.org/archives/list/[email protected]/message/TE7F54W5O5RS4ZMAAC7YK3CZWQXIDSKB/ https://security.gentoo.org/glsa/202401-34

Known Exploited Vulnerability Information

Source Added Date
CISA 2023-10-02 00:00:00 UTC