Skip to content

libwebp CVE

High
Brooooooklyn published GHSA-4vjr-crvh-383h Sep 27, 2023

Package

npm @napi-rs/image (npm)

Affected versions

<= 1.6.1

Patched versions

1.7.0

Description

Impact

Heap buffer overflow in libwebp allows a remote attacker to perform an out of bounds memory write via a crafted webp image.

References

Severity

High
8.8
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE ID

CVE-2023-4863

Weaknesses

No CWEs

Credits