CERT-In Advisory
CIAD-2023-0033
Heap Buffer Overflow Vulnerability in VP8 encoding in libvpx
Original Issue Date: September 29, 2023
Severity Rating: Critical
Software Affected
- libvpx versions prior to 1.13.1
- Google Chrome for Desktop versions prior to 117.0.5938.132 (for Windows, Mac and Linux)
- Mozilla Firefox versions prior to 118.0.1
- Mozilla Firefox versions prior to ESR 115.3.1
- Mozilla Firefox Focus for Android versions prior to 118.1
- Mozilla Firefox for Android versions prior to 118.1
Overview
A vulnerability has been reported in VP8 Mediastream in libvpx which could allow the remote attacker to execute arbitrary code or cause denial of service conditions on the targeted system.
Description
This vulnerability exists in VP8 Mediastream in libvpx of various products due to improper bound checks. A remote attacker could exploit this vulnerability by sending a crafted HTML page which when executed could result in heap buffer overflow conditions.
Successful exploitation of this vulnerability could allow the remote attacker to execute arbitrary code or cause denial of service conditions on the targeted system.
Note: This vulnerability is being exploited in the wild. Users are advised to patch the vulnerable devices immediately.
Solution
Apply appropriate upgrade to the latest product versions immediately or once they are released.
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html
Mozilla
https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/
References
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html
https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/
https://bugzilla.redhat.com/show_bug.cgi?id=2241191
https://www.openwall.com/lists/oss-security/2023/09/28/5
CVE Name
CVE-2023-5217
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|