CVE-2018-25010: Buffer Overflow
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
Other sources
ActionKit. An input validation issue was addressed with improved input validation.
— Apple
Analytics. This issue was addressed with a new entitlement.
— Apple
Audio. This issue was addressed with improved checks.
— Apple
AVEVideoEncoder. A memory corruption issue was addressed with improved state management.
— Apple
CoreAudio. A logic issue was addressed with improved validation.
— Apple
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30763
- CVE-2021-30871
- CVE-2021-30781
- CVE-2021-30748
- CVE-2021-30775
- CVE-2021-30776
- CVE-2021-30786
- CVE-2021-30789
- CVE-2021-30774
- CVE-2021-30780
- CVE-2021-30768
- CVE-2021-30804
- CVE-2021-30760
- CVE-2021-30788
- CVE-2021-30759
- CVE-2021-30773
- CVE-2021-30802
- CVE-2021-30779
- CVE-2021-30785
- CVE-2021-30769
- CVE-2021-30770
- CVE-2021-3518
- CVE-2018-25010
- CVE-2018-25011
- CVE-2018-25014
- CVE-2020-36328
- CVE-2020-36329
- CVE-2020-36330
- CVE-2020-36331
- CVE-2021-30796
- CVE-2021-30792
- CVE-2021-30791
- CVE-2021-30798
- CVE-2021-30758
- CVE-2021-30795
- CVE-2021-30797
- CVE-2021-30799
- CVE-2021-30800
Frequently Asked Questions
What is CVE-2018-25010?
CVE-2018-25010 is a heap-based buffer overflow vulnerability found in libwebp in versions before 1.0.1 in ApplyFilter().
What is the severity of CVE-2018-25010?
CVE-2018-25010 has a severity level of 9.1 (Critical).
Which software are affected by CVE-2018-25010?
CVE-2018-25010 affects libwebp in versions before 1.0.1 in ApplyFilter(), Mozilla Firefox ESR, and Redhat Enterprise Linux 8.0.
How do I fix CVE-2018-25010?
To fix CVE-2018-25010, update libwebp to version 1.0.1 or later. For Mozilla Firefox ESR, update to a version that includes a fix for this vulnerability. Redhat Enterprise Linux users should apply the necessary security patches.
Where can I find more information about CVE-2018-25010?
More information about CVE-2018-25010 can be found at the following references:<br> - https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9105<br> - https://bugzilla.redhat.com/show_bug.cgi?id=1956918<br> - https://chromium.googlesource.com/webm/libwebp/+/1344a2e947c749d231141a295327e5b99b444d63