USN-6078-1: libwebp vulnerability
Published May 16, 2023
·Updated
Irvan Kurniawan discovered that libwebp incorrectly handled certain memory operations. If a user or automated system were tricked into opening a specially crafted image file, a remote attacker could use this issue to cause libwebp to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software
30 affected componentsFixes available
All of the following
ubuntu/libwebp7<1.2.4-0.1ubuntu0.23.04.1
1.2.4-0.1ubuntu0.23.04.1
Ubuntu Ubuntu=23.04
All of the following
ubuntu/libwebpmux3<1.2.4-0.1ubuntu0.23.04.1
1.2.4-0.1ubuntu0.23.04.1
Ubuntu Ubuntu=23.04
All of the following
ubuntu/libwebpdemux2<1.2.4-0.1ubuntu0.23.04.1
1.2.4-0.1ubuntu0.23.04.1
Ubuntu Ubuntu=23.04
All of the following
ubuntu/libwebp7<1.2.2-2ubuntu0.22.10.1
1.2.2-2ubuntu0.22.10.1
Ubuntu Ubuntu=22.10
All of the following
ubuntu/libwebpmux3<1.2.2-2ubuntu0.22.10.1
1.2.2-2ubuntu0.22.10.1
Ubuntu Ubuntu=22.10
All of the following
ubuntu/libwebpdemux2<1.2.2-2ubuntu0.22.10.1
1.2.2-2ubuntu0.22.10.1
Ubuntu Ubuntu=22.10
All of the following
ubuntu/libwebp7<1.2.2-2ubuntu0.22.04.1
1.2.2-2ubuntu0.22.04.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libwebpmux3<1.2.2-2ubuntu0.22.04.1
1.2.2-2ubuntu0.22.04.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libwebpdemux2<1.2.2-2ubuntu0.22.04.1
1.2.2-2ubuntu0.22.04.1
Ubuntu Ubuntu=22.04
All of the following
ubuntu/libwebp6<0.6.1-2ubuntu0.20.04.2
0.6.1-2ubuntu0.20.04.2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libwebpmux3<0.6.1-2ubuntu0.20.04.2
0.6.1-2ubuntu0.20.04.2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libwebpdemux2<0.6.1-2ubuntu0.20.04.2
0.6.1-2ubuntu0.20.04.2
Ubuntu Ubuntu=20.04
All of the following
ubuntu/libwebp6<0.6.1-2ubuntu0.18.04.2
0.6.1-2ubuntu0.18.04.2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libwebpmux3<0.6.1-2ubuntu0.18.04.2
0.6.1-2ubuntu0.18.04.2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/libwebpdemux2<0.6.1-2ubuntu0.18.04.2
0.6.1-2ubuntu0.18.04.2
Ubuntu Ubuntu=18.04
Event History
May 16, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is USN-6078-1.
2
What is the title of this security vulnerability?
The title of this security vulnerability is 'libwebp vulnerability'.
3
Who discovered the libwebp vulnerability?
The libwebp vulnerability was discovered by Irvan Kurniawan.
4
What is the impact of this vulnerability?
This vulnerability could allow a remote attacker to cause a denial of service or possibly execute arbitrary code.
5
How can I fix this vulnerability?
To fix this vulnerability, update libwebp to version 1.2.4-0.1ubuntu0.23.04.1 or later.