CVE-2018-25014: Input Validation
Published May 4, 2021
·Updated
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
Credit
George Nosenko, JunDong Xie(Ant Security Light), ryuzaki, Mickey Jin@@patch1t(Trend Micro), Sunglin(Knownsec 404 team), Yizhuo Wang(Group of Software Security In Progress), Tim Michaud@@TimGMichaud(Zoom Video Communications), Linus Henze (pinauten.de), Csaba Fitzl@@theevilbit(Offensive Security), tr3e(Trend Micro Zero Day Initiative), hjy79425575(Trend Micro Zero Day Initiative), Matthew Denton(Google Chrome Security), Jzhu(Baidu Security), Ye Zhang@@co0py_Cat(Baidu Security), CFF(Topsec Alpha Team), CVE-2021-3518, CVE-2018-25010, CVE-2018-25011, CVE-2018-25014, CVE-2020-36328, CVE-2020-36329, CVE-2020-36330, CVE-2020-36331, Anonymous(Trend Micro Zero Day Initiative), Christoph Guttandin(Media Codings), Sergei Glazunov(Google Project Zero), Ivan Fratric(Google Project Zero), vm_call, Nozhdar Abdulkhaleq Shukri, Zachary Keffaber@@QuickUpdate5, Denis Tokarev@@illusionofcha0s, tr3e
Affected Software
7 affected componentsFixes available
debian/libwebp
0.6.1-2+deb10u10.6.1-2+deb10u30.6.1-2.1+deb11u21.2.4-0.2+deb12u11.3.2-0.3
redhat/libwebp<1.0.1
1.0.1
webmproject Libwebp<1.0.1
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
Apple iOS<14.7
14.7
Apple iPadOS<14.7
14.7
Remediation
Patch Available
Event History
May 21, 2021
CVE Published
via MITRE·04:27 PM
Data Sourced
via MITRE·04:27 PM
DescriptionWeakness
Feb 24, 2026
Data Sourced
via Apple·07:00 PM
DescriptionWeaknessAffected Software
Updated
via Apple·07:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-25014?
CVE-2018-25014 is a vulnerability found in libwebp in versions before 1.0.1 in ReadSymbol().
2
What is the severity of CVE-2018-25014?
The severity of CVE-2018-25014 is critical with a CVSS score of 9.8.
3
What is affected by CVE-2018-25014?
The vulnerability affects libwebp versions before 1.0.1 in ReadSymbol().
4
How do I fix CVE-2018-25014 in Debian-based systems?
To fix the vulnerability in Debian-based systems, update to libwebp version 0.6.1-2+deb10u1, 0.6.1-2+deb10u3, 0.6.1-2.1+deb11u2, 1.2.4-0.2+deb12u1, or 1.3.2-0.3.
5
How do I fix CVE-2018-25014 in Redhat Enterprise Linux 7.0?
To fix the vulnerability in Redhat Enterprise Linux 7.0, apply the necessary security updates.
6
How do I fix CVE-2018-25014 in Redhat Enterprise Linux 8.0?
To fix the vulnerability in Redhat Enterprise Linux 8.0, apply the necessary security updates.