CVE-2020-36328: Buffer Overflow
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Other sources
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in WebPDecodeInto functions.
Reference: https://bugs.chromium.org/p/webp/issues/detail?id=383
— Red Hat
ActionKit. An input validation issue was addressed with improved input validation.
— Apple
Analytics. This issue was addressed with a new entitlement.
— Apple
Audio. This issue was addressed with improved checks.
— Apple
AVEVideoEncoder. A memory corruption issue was addressed with improved state management.
— Apple
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2021-30763
- CVE-2021-30871
- CVE-2021-30781
- CVE-2021-30748
- CVE-2021-30775
- CVE-2021-30776
- CVE-2021-30786
- CVE-2021-30789
- CVE-2021-30774
- CVE-2021-30780
- CVE-2021-30768
- CVE-2021-30804
- CVE-2021-30760
- CVE-2021-30788
- CVE-2021-30759
- CVE-2021-30773
- CVE-2021-30802
- CVE-2021-30779
- CVE-2021-30785
- CVE-2021-30769
- CVE-2021-30770
- CVE-2021-3518
- CVE-2018-25010
- CVE-2018-25011
- CVE-2018-25014
- CVE-2020-36328
- CVE-2020-36329
- CVE-2020-36330
- CVE-2020-36331
- CVE-2021-30796
- CVE-2021-30792
- CVE-2021-30791
- CVE-2021-30798
- CVE-2021-30758
- CVE-2021-30795
- CVE-2021-30797
- CVE-2021-30799
- CVE-2021-30800
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-36328.
What is the severity of CVE-2020-36328?
The severity of CVE-2020-36328 is critical with a CVSS score of 9.8.
How does CVE-2020-36328 impact system security?
CVE-2020-36328 poses a threat to data confidentiality, integrity, and system availability.
Which software versions are affected by CVE-2020-36328?
Versions before 1.0.1 of libwebp are affected by CVE-2020-36328.
Where can I find more information about CVE-2020-36328?
You can find more information about CVE-2020-36328 in the provided references.