CVE-2023-6349: Heap overflow in libvpx
A heap overflow vulnerability exists in libvpx - Encoding a frame that has larger dimensions than the originally configured size with VP9 may result in a heap overflow in libvpx. We recommend upgrading to version 1.13.1 or above
Other sources
WebM Project libvpx is vulnerable to a heap-based buffer overflow, caused by improper bounds checking when encoding a frame. By sending a specially crafted request, a local authenticated attacker could overflow a buffer and execute arbitrary code on the system.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6349?
CVE-2023-6349 is classified as a high severity vulnerability due to the potential for a heap overflow causing crashes or remote code execution.
How do I fix CVE-2023-6349?
To fix CVE-2023-6349, upgrade libvpx to version 1.13.1 or above.
Which software is affected by CVE-2023-6349?
CVE-2023-6349 affects libvpx and is also noted in IBM QRadar SIEM and QRadar Incident Forensics prior to version 7.5.0 UP9 IF03.
What does CVE-2023-6349 exploit?
CVE-2023-6349 exploits a heap overflow vulnerability that occurs when encoding a frame with larger dimensions than originally configured.
Can CVE-2023-6349 lead to any security risks?
Yes, CVE-2023-6349 can lead to security risks including potential remote code execution and application crashes.