CVE-2023-5217: Heap buffer overflow in vp8 encoding in libvpx
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
Other sources
Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.
— CISA
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
— GitHub
Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.
— Mozilla
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information. Google is aware that an exploit for CVE-2023-5217 exists in the wild.
— Microsoft
WebRTC. Description: The issue was addressed by updating to libvpx 1.13.1.
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/libvpxto a version that resolves this vulnerability.Fixed in 1.12.0-1.1Fixed in 1.9.0-1+deb11u1Fixed in 1.12.0-1+deb12u1 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 27.0.0-beta.8 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 26.2.4 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 25.8.4 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 24.8.5 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 22.3.25 - Upgrade
Upgrade
Firefoxto a version that resolves this vulnerability.Fixed in 118.0.1 - Upgrade
Upgrade
Firefox ESRto a version that resolves this vulnerability.Fixed in 115.3.1 - Upgrade
Upgrade
Thunderbirdto a version that resolves this vulnerability.Fixed in 115.3.1 - Upgrade
Upgrade
Google Chrome (Trace Event)to a version that resolves this vulnerability.Fixed in 117.0.5938.132 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 16.7.1 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 16.7.1 - Upgrade
Upgrade
Apple iOS and iPadOSto a version that resolves this vulnerability.Fixed in 17.0.3 - Upgrade
Upgrade
Apple iOS, iPadOS, and macOSto a version that resolves this vulnerability.Fixed in 17.0.3 - Upgrade
Upgrade
redhat/chromium-browserto a version that resolves this vulnerability.Fixed in 117.0.5938.132 - Upgrade
Upgrade
debian/chromiumto a version that resolves this vulnerability.Fixed in 120.0.6099.224-1~deb11u1Fixed in 150.0.7871.100-1~deb12u1Fixed in 150.0.7871.181-1~deb12u1Fixed in 150.0.7871.100-1~deb13u1Fixed in 150.0.7871.181-1~deb13u1Fixed in 150.0.7871.124-1Fixed in 150.0.7871.181-1 - Upgrade
Upgrade
debian/firefox-esrto a version that resolves this vulnerability.Fixed in 115.14.0esr-1~deb11u1Fixed in 140.13.0esr-1~deb11u1 - Upgrade
Upgrade
debian/libvpxto a version that resolves this vulnerability.Fixed in 1.9.0-1+deb11u3Fixed in 1.9.0-1+deb11u5Fixed in 1.12.0-1+deb12u5Fixed in 1.15.0-2.1+deb13u1Fixed in 1.16.0-3 - Upgrade
Upgrade
debian/thunderbirdto a version that resolves this vulnerability.Fixed in 1:115.12.0-1~deb11u1Fixed in 1:140.12.0esr-1~deb11u1Fixed in 1:140.12.0esr-1~deb12u1Fixed in 1:140.12.0esr-1~deb13u1Fixed in 1:140.12.0esr-1 - Upgrade
Upgrade
libvpxto a version that resolves this vulnerability.Fixed in 1.13.1 - Compensating control
If mitigations are unavailable, discontinue use of the affected product per vendor guidance.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-5217?
CVE-2023-5217 is a heap buffer overflow vulnerability in the vp8 encoding in libvpx in Google Chrome and Microsoft Edge (Chromium-based) that allows a remote attacker to potentially exploit heap corruption.
How severe is CVE-2023-5217?
CVE-2023-5217 has a severity rating of High.
Which software products are affected by CVE-2023-5217?
CVE-2023-5217 affects Google Chrome, Microsoft Edge (Chromium-based), and libvpx.
How can I fix CVE-2023-5217 in Microsoft Edge?
To fix CVE-2023-5217 in Microsoft Edge, update to version 117.0.5938.132 or later.
How can I fix CVE-2023-5217 in Google Chrome?
To fix CVE-2023-5217 in Google Chrome, update to version 117.0.5938.132 or later.