CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx

Published Sep 25, 2023
·
Updated

Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx

Other sources

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

CISA

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

GitHub

Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.

Mozilla

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2023-5217 exists in the wild.

Microsoft

WebRTC. Description: The issue was addressed by updating to libvpx 1.13.1.

Credit

Clément Lecigne(Google's Threat Analysis Group)

Affected Software

56 affected componentsFixes available
debian/libvpx<=1.9.0-1, <=1.12.0-1
1.12.0-1.11.9.0-1+deb11u11.12.0-1+deb12u1
npm/electron>=27.0.0-alpha.1<27.0.0-beta.8
27.0.0-beta.8
npm/electron>=26.0.0<26.2.4
26.2.4
npm/electron>=25.0.0<25.8.4
25.8.4
npm/electron>=24.0.0<24.8.5
24.8.5
npm/electron<22.3.25
22.3.25
Microsoft Edge (Chromium-based)
Microsoft Edge<117.0.2045.47
Microsoft Teams for Mac
Microsoft Teams for Desktop
Google Chromium libvpx
Mozilla Firefox<118.0.1
118.0.1
Mozilla Firefox ESR<115.3.1
115.3.1
All of the following
Mozilla Firefox Focus=118.1
Google Android
All of the following
Mozilla Firefox=118.1
Google Android
Mozilla Thunderbird<115.3.1
115.3.1
Google Chrome<117.0.5938.132
117.0.5938.132
webmproject libvpx=1.13.1
Google Chrome<117.0.5938.132
Mozilla Firefox<118.0.1
Mozilla Firefox Android<118.1
Mozilla Firefox ESR<115.3.1
Mozilla Firefox Focus Android<118.1
Apple iOS<16.7.1
16.7.1
Apple iPadOS<16.7.1
16.7.1
Apple iOS<17.0.3
17.0.3
Apple iPadOS<17.0.3
17.0.3
redhat/chromium-browser<117.0.5938.132
117.0.5938.132
webmproject libvpx<1.13.1
Microsoft Edge=116.0.1938.98
Microsoft Edge=117.0.2045.47
Microsoft Edge Chromium=116.0.5845.229
Microsoft Edge Chromium=117.0.5938.132
Mozilla Firefox<115.3.1
Mozilla Firefox<118.0.1
Mozilla Firefox Android<118.1
Mozilla Thunderbird<115.3.1
Fedoraproject Fedora=37
Fedoraproject Fedora=38
Fedoraproject Fedora=39
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Debian Debian Linux=12.0
Apple iPadOS>=17.0<17.0.3
Apple iPadOS=16.7
Apple iPhone OS>=17.0<17.0.3
Apple iPhone OS=16.7
Google Chrome<117.0.5938.132
redhat Enterprise Linux=9.0
debian/chromium
120.0.6099.224-1~deb11u1150.0.7871.100-1~deb12u1150.0.7871.181-1~deb12u1150.0.7871.100-1~deb13u1150.0.7871.181-1~deb13u1150.0.7871.124-1150.0.7871.181-1
debian/firefox<=152.0.6-1
debian/firefox-esr<=140.12.0esr-1~deb12u1, <=140.13.0esr-1~deb12u1, <=140.12.0esr-1~deb13u1, <=140.13.0esr-1~deb13u1, <=140.13.0esr-2
115.14.0esr-1~deb11u1140.13.0esr-1~deb11u1
debian/libvpx
1.9.0-1+deb11u31.9.0-1+deb11u51.12.0-1+deb12u51.15.0-2.1+deb13u11.16.0-3
debian/thunderbird
1:115.12.0-1~deb11u11:140.12.0esr-1~deb11u11:140.12.0esr-1~deb12u11:140.12.0esr-1~deb13u11:140.12.0esr-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/libvpx to a version that resolves this vulnerability.

    Fixed in 1.12.0-1.1Fixed in 1.9.0-1+deb11u1Fixed in 1.12.0-1+deb12u1
  2. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 27.0.0-beta.8
  3. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 26.2.4
  4. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 25.8.4
  5. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 24.8.5
  6. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 22.3.25
  7. Upgrade

    Upgrade Firefox to a version that resolves this vulnerability.

    Fixed in 118.0.1
  8. Upgrade

    Upgrade Firefox ESR to a version that resolves this vulnerability.

    Fixed in 115.3.1
  9. Upgrade

    Upgrade Thunderbird to a version that resolves this vulnerability.

    Fixed in 115.3.1
  10. Upgrade

    Upgrade Google Chrome (Trace Event) to a version that resolves this vulnerability.

    Fixed in 117.0.5938.132
  11. Upgrade

    Upgrade Apple iOS and iPadOS to a version that resolves this vulnerability.

    Fixed in 16.7.1
  12. Upgrade

    Upgrade Apple iOS, iPadOS, and macOS to a version that resolves this vulnerability.

    Fixed in 16.7.1
  13. Upgrade

    Upgrade Apple iOS and iPadOS to a version that resolves this vulnerability.

    Fixed in 17.0.3
  14. Upgrade

    Upgrade Apple iOS, iPadOS, and macOS to a version that resolves this vulnerability.

    Fixed in 17.0.3
  15. Upgrade

    Upgrade redhat/chromium-browser to a version that resolves this vulnerability.

    Fixed in 117.0.5938.132
  16. Upgrade

    Upgrade debian/chromium to a version that resolves this vulnerability.

    Fixed in 120.0.6099.224-1~deb11u1Fixed in 150.0.7871.100-1~deb12u1Fixed in 150.0.7871.181-1~deb12u1Fixed in 150.0.7871.100-1~deb13u1Fixed in 150.0.7871.181-1~deb13u1Fixed in 150.0.7871.124-1Fixed in 150.0.7871.181-1
  17. Upgrade

    Upgrade debian/firefox-esr to a version that resolves this vulnerability.

    Fixed in 115.14.0esr-1~deb11u1Fixed in 140.13.0esr-1~deb11u1
  18. Upgrade

    Upgrade debian/libvpx to a version that resolves this vulnerability.

    Fixed in 1.9.0-1+deb11u3Fixed in 1.9.0-1+deb11u5Fixed in 1.12.0-1+deb12u5Fixed in 1.15.0-2.1+deb13u1Fixed in 1.16.0-3
  19. Upgrade

    Upgrade debian/thunderbird to a version that resolves this vulnerability.

    Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.12.0esr-1
  20. Upgrade

    Upgrade libvpx to a version that resolves this vulnerability.

    Fixed in 1.13.1
  21. Compensating control

    If mitigations are unavailable, discontinue use of the affected product per vendor guidance.

Event History

Sep 25, 2023
CVE Published
12:00 AM
Known Exploited
12:00 AM
Sep 28, 2023
Data Sourced
via Red Hat·02:00 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·03:23 PM
Data Sourced
via MITRE·03:23 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·06:30 PM
Nov 28, 2023
News Published
09:24 PM
Dec 20, 2023
News Published
09:41 PM
Jan 16, 2024
News Published
via BleepingComputer·07:13 PM
Jan 20, 2024
News Published
via BleepingComputer·07:14 PM
Feb 17, 2024
Data Sourced
via Launchpad·12:50 AM
Description
Mar 27, 2024
News Published
via The Register·02:00 PM
News Published
via The Register·02:04 PM
Dec 21, 2024
Data Sourced
via Ubuntu·05:35 AM
RemedyDescriptionSeverityAffected Software
Jul 27, 2026
Data Sourced
via Debian·12:43 PM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2023-5217?

CVE-2023-5217 is a heap buffer overflow vulnerability in the vp8 encoding in libvpx in Google Chrome and Microsoft Edge (Chromium-based) that allows a remote attacker to potentially exploit heap corruption.

2

How severe is CVE-2023-5217?

CVE-2023-5217 has a severity rating of High.

3

Which software products are affected by CVE-2023-5217?

CVE-2023-5217 affects Google Chrome, Microsoft Edge (Chromium-based), and libvpx.

4

How can I fix CVE-2023-5217 in Microsoft Edge?

To fix CVE-2023-5217 in Microsoft Edge, update to version 117.0.5938.132 or later.

5

How can I fix CVE-2023-5217 in Google Chrome?

To fix CVE-2023-5217 in Google Chrome, update to version 117.0.5938.132 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203