| CERT-In Advisory  
                                                                      CIAD-2023-0033Heap Buffer Overflow Vulnerability in VP8 encoding in libvpxOriginal Issue Date: September 29, 2023
 Severity Rating: Critical
 Software Affected  
libvpx versions prior to 1.13.1Google Chrome for Desktop versions prior to 117.0.5938.132 (for Windows, Mac and Linux)Mozilla Firefox versions prior to 118.0.1Mozilla Firefox versions prior to ESR 115.3.1Mozilla Firefox Focus for Android versions prior to 118.1Mozilla Firefox for Android versions prior to 118.1 Overview A vulnerability has been reported in VP8 Mediastream  in libvpx which could allow the remote attacker to execute arbitrary code or cause denial of service conditions on the targeted system. DescriptionThis vulnerability exists in VP8 Mediastream in libvpx of various products due to improper bound checks. A remote attacker could exploit this vulnerability by sending a crafted HTML page which when executed could result in heap buffer overflow conditions. 
 Successful exploitation of this vulnerability could allow the remote attacker to execute arbitrary code or cause denial of service conditions on the targeted system.
 
 Note: This vulnerability is being exploited in the wild. Users are advised to patch the vulnerable devices immediately.
 
 
 Solution Apply appropriate upgrade to the latest product versions immediately or once they are released. 
 Vendor InformationGoogle Chrome https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html
 Mozilla
 https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/
 
 References  https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html
 https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/
 https://bugzilla.redhat.com/show_bug.cgi?id=2241191
 https://www.openwall.com/lists/oss-security/2023/09/28/5
 
 CVE NameDisclaimerCVE-2023-5217
 
 The information provided herein is on "as is" basis, without warranty of any kind. Contact Information Email: info@cert-in.org.in  Phone: +91-11-24368572Postal address Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology
 Government of India
 Electronics Niketan
 6, CGO Complex, Lodhi Road,
 New Delhi - 110 003
 India
   |