CVE-2018-25011: Buffer Overflow
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
Other sources
ActionKit. An input validation issue was addressed with improved input validation.
— Apple
Analytics. This issue was addressed with a new entitlement.
— Apple
Audio. This issue was addressed with improved checks.
— Apple
AVEVideoEncoder. A memory corruption issue was addressed with improved state management.
— Apple
CoreAudio. A logic issue was addressed with improved validation.
— Apple
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30763
- CVE-2021-30871
- CVE-2021-30781
- CVE-2021-30748
- CVE-2021-30775
- CVE-2021-30776
- CVE-2021-30786
- CVE-2021-30789
- CVE-2021-30774
- CVE-2021-30780
- CVE-2021-30768
- CVE-2021-30804
- CVE-2021-30760
- CVE-2021-30788
- CVE-2021-30759
- CVE-2021-30773
- CVE-2021-30802
- CVE-2021-30779
- CVE-2021-30785
- CVE-2021-30769
- CVE-2021-30770
- CVE-2021-3518
- CVE-2018-25010
- CVE-2018-25011
- CVE-2018-25014
- CVE-2020-36328
- CVE-2020-36329
- CVE-2020-36330
- CVE-2020-36331
- CVE-2021-30796
- CVE-2021-30792
- CVE-2021-30791
- CVE-2021-30798
- CVE-2021-30758
- CVE-2021-30795
- CVE-2021-30797
- CVE-2021-30799
- CVE-2021-30800
Frequently Asked Questions
What is CVE-2018-25011?
CVE-2018-25011 is a heap-based buffer overflow vulnerability found in libwebp versions before 1.0.1 in PutLE16().
How does CVE-2018-25011 affect IBM Cloud Pak for Security?
IBM Cloud Pak for Security (CP4S) versions up to and including 1.7.2.0 are affected by CVE-2018-25011.
What is the severity of CVE-2018-25011?
CVE-2018-25011 has a severity score of 9.8 (Critical).
How can CVE-2018-25011 be exploited?
An attacker can exploit CVE-2018-25011 by sending an overly long argument, causing a heap-based buffer overflow that could lead to arbitrary code execution or application crashes.
Is there a fix for CVE-2018-25011?
Debian has released fixes for CVE-2018-25011 in the libwebp package. It is recommended to update to the latest fixed version.