CVE-2018-25012: Buffer Overflow
Published May 4, 2021
·Updated
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().
Affected Software
3 affected componentsFixes available
redhat/libwebp<1.0.1
1.0.1
webmproject Libwebp<1.0.1
redhat Enterprise Linux=8.0
Remediation
Patch Available
Event History
May 21, 2021
CVE Published
via MITRE·04:26 PM
Data Sourced
via MITRE·04:26 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-25012?
CVE-2018-25012 is a heap-based buffer overflow vulnerability found in libwebp versions before 1.0.1 in GetLE24().
2
How severe is CVE-2018-25012?
CVE-2018-25012 is classified as critical with a severity value of 9.1/10.
3
Which software is affected by CVE-2018-25012?
Mozilla Firefox ESR and Redhat Enterprise Linux 8.0 are affected by CVE-2018-25012.
4
How can I fix CVE-2018-25012?
To fix CVE-2018-25012, you should update libwebp to version 1.0.1 or later.
5
What are the references for CVE-2018-25012?
The references for CVE-2018-25012 are: [1] [2] [3].