CVE-2018-25014: Input Validation
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
Other sources
ActionKit. An input validation issue was addressed with improved input validation.
— Apple
Analytics. This issue was addressed with a new entitlement.
— Apple
Audio. This issue was addressed with improved checks.
— Apple
AVEVideoEncoder. A memory corruption issue was addressed with improved state management.
— Apple
CoreAudio. A logic issue was addressed with improved validation.
— Apple
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30763
- CVE-2021-30871
- CVE-2021-30781
- CVE-2021-30748
- CVE-2021-30775
- CVE-2021-30776
- CVE-2021-30786
- CVE-2021-30789
- CVE-2021-30774
- CVE-2021-30780
- CVE-2021-30768
- CVE-2021-30804
- CVE-2021-30760
- CVE-2021-30788
- CVE-2021-30759
- CVE-2021-30773
- CVE-2021-30802
- CVE-2021-30779
- CVE-2021-30785
- CVE-2021-30769
- CVE-2021-30770
- CVE-2021-3518
- CVE-2018-25010
- CVE-2018-25011
- CVE-2018-25014
- CVE-2020-36328
- CVE-2020-36329
- CVE-2020-36330
- CVE-2020-36331
- CVE-2021-30796
- CVE-2021-30792
- CVE-2021-30791
- CVE-2021-30798
- CVE-2021-30758
- CVE-2021-30795
- CVE-2021-30797
- CVE-2021-30799
- CVE-2021-30800
Frequently Asked Questions
What is CVE-2018-25014?
CVE-2018-25014 is a vulnerability found in libwebp in versions before 1.0.1 in ReadSymbol().
What is the severity of CVE-2018-25014?
The severity of CVE-2018-25014 is critical with a CVSS score of 9.8.
What is affected by CVE-2018-25014?
The vulnerability affects libwebp versions before 1.0.1 in ReadSymbol().
How do I fix CVE-2018-25014 in Debian-based systems?
To fix the vulnerability in Debian-based systems, update to libwebp version 0.6.1-2+deb10u1, 0.6.1-2+deb10u3, 0.6.1-2.1+deb11u2, 1.2.4-0.2+deb12u1, or 1.3.2-0.3.
How do I fix CVE-2018-25014 in Redhat Enterprise Linux 7.0?
To fix the vulnerability in Redhat Enterprise Linux 7.0, apply the necessary security updates.
How do I fix CVE-2018-25014 in Redhat Enterprise Linux 8.0?
To fix the vulnerability in Redhat Enterprise Linux 8.0, apply the necessary security updates.