CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx
Published Sep 25, 2023
·Updated
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
Credit
Clément Lecigne(Google's Threat Analysis Group)
Affected Software
56 affected componentsFixes available
debian/libvpx<=1.9.0-1, <=1.12.0-1
1.12.0-1.11.9.0-1+deb11u11.12.0-1+deb12u1
npm/electron>=27.0.0-alpha.1<27.0.0-beta.8
27.0.0-beta.8
npm/electron>=26.0.0<26.2.4
26.2.4
npm/electron>=25.0.0<25.8.4
25.8.4
npm/electron>=24.0.0<24.8.5
24.8.5
npm/electron<22.3.25
22.3.25
Microsoft Edge (Chromium-based)
Microsoft Edge<117.0.2045.47
Microsoft Teams for Mac
Microsoft Teams for Desktop
Google Chromium libvpx
Mozilla Firefox<118.0.1
118.0.1
Mozilla Firefox ESR<115.3.1
115.3.1
All of the following
Mozilla Firefox Focus=118.1
Google Android
All of the following
Mozilla Firefox=118.1
Google Android
Mozilla Thunderbird<115.3.1
115.3.1
Google Chrome<117.0.5938.132
117.0.5938.132
webmproject libvpx=1.13.1
Google Chrome<117.0.5938.132
Mozilla Firefox<118.0.1
Mozilla Firefox Android<118.1
Mozilla Firefox ESR<115.3.1
Mozilla Firefox Focus Android<118.1
Apple iOS<16.7.1
16.7.1
Apple iPadOS<16.7.1
16.7.1
Apple iOS<17.0.3
17.0.3
Apple iPadOS<17.0.3
17.0.3
redhat/chromium-browser<117.0.5938.132
117.0.5938.132
webmproject libvpx<1.13.1
Microsoft Edge=116.0.1938.98
Microsoft Edge=117.0.2045.47
Microsoft Edge Chromium=116.0.5845.229
Microsoft Edge Chromium=117.0.5938.132
Mozilla Firefox<115.3.1
Mozilla Firefox<118.0.1
Mozilla Firefox Android<118.1
Mozilla Thunderbird<115.3.1
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Debian Debian Linux=12.0
Apple iPadOS>=17.0<17.0.3
Apple iPadOS=16.7
Apple iPhone OS>=17.0<17.0.3
Apple iPhone OS=16.7
Google Chrome<117.0.5938.132
redhat Enterprise Linux=9.0
debian/chromium
120.0.6099.224-1~deb11u1147.0.7727.137-1~deb12u1148.0.7778.178-1~deb12u1147.0.7727.137-1~deb13u1148.0.7778.178-1~deb13u1148.0.7778.178-1
debian/firefox<=151.0.1-1
debian/firefox-esr<=140.10.2esr-1~deb12u1, <=140.11.0esr-1~deb12u1, <=140.10.2esr-1~deb13u1, <=140.11.0esr-1~deb13u1, <=140.11.0esr-1
115.14.0esr-1~deb11u1140.11.0esr-1~deb11u1
debian/libvpx
1.9.0-1+deb11u31.9.0-1+deb11u51.12.0-1+deb12u51.15.0-2.1+deb13u11.16.0-3
debian/thunderbird
1:115.12.0-1~deb11u11:140.11.0esr-1~deb11u11:140.10.1esr-1~deb12u11:140.11.0esr-1~deb12u11:140.10.1esr-1~deb13u11:140.11.0esr-1~deb13u11:140.11.0esr-1
Remediation
Patch Available
Patch Available
Information
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Event History
Sep 25, 2023
CVE Published
12:00 AM
Known Exploited
12:00 AM
Sep 28, 2023
Data Sourced
via Red Hat·02:00 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Nov 28, 2023
News Published
09:24 PM
Dec 20, 2023
News Published
09:41 PM
Jan 16, 2024
News Published
via BleepingComputer·07:13 PM
Jan 20, 2024
News Published
via BleepingComputer·07:14 PM
Feb 17, 2024
Data Sourced
via Launchpad·12:50 AM
Description
Mar 27, 2024
News Published
via The Register·02:00 PM
News Published
via The Register·02:04 PM
Dec 21, 2024
Data Sourced
via Ubuntu·05:35 AM
RemedyDescriptionSeverityAffected Software
May 25, 2026
Data Sourced
via Debian·10:40 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2023-5217?
CVE-2023-5217 is a heap buffer overflow vulnerability in the vp8 encoding in libvpx in Google Chrome and Microsoft Edge (Chromium-based) that allows a remote attacker to potentially exploit heap corruption.
2
How severe is CVE-2023-5217?
CVE-2023-5217 has a severity rating of High.
3
Which software products are affected by CVE-2023-5217?
CVE-2023-5217 affects Google Chrome, Microsoft Edge (Chromium-based), and libvpx.
4
How can I fix CVE-2023-5217 in Microsoft Edge?
To fix CVE-2023-5217 in Microsoft Edge, update to version 117.0.5938.132 or later.
5
How can I fix CVE-2023-5217 in Google Chrome?
To fix CVE-2023-5217 in Google Chrome, update to version 117.0.5938.132 or later.