Wind River Support Network

HomeDefectsLIN1018-7696
Fixed

LIN1018-7696 : Security Advisory - libwebp - CVE-2020-36328

Created: May 23, 2021    Updated: Jun 15, 2021
Resolved Date: Jun 15, 2021
Found In Version: 10.18.44.1
Severity: Standard
Applicable for: Wind River Linux LTS 18
Component/s: Userspace

Description

A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CREATE(Triage):(User=admin) [CVE-2020-36328|https://nvd.nist.gov/vuln/detail/CVE-2020-36328]

CVEs


Live chat
Online