imPC@ndo IT

Tracker / CVE-2023-4863

CVE-2023-4863

Exploited High 8.8

Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)

Affected products and versions

bandisoft honeyview · … → 5.51
bentley seequent_leapfrog · … → 2023.2
debian debian_linux
fedoraproject fedora
google chrome · … → 116.0.5845.187
microsoft edge_chromium · … → 116.0.1938.81
microsoft teams · … → 1.6.00.26463
microsoft teams · … → 1.6.00.26474
microsoft webp_image_extension · … → 1.0.62681.0
mozilla firefox · … → 102.15.1
mozilla firefox · … → 117.0.1
mozilla firefox · 115.1.0 → 115.2.1
mozilla thunderbird · … → 102.15.1
mozilla thunderbird · 115.0 → 115.2.2
netapp active_iq_unified_manager
webmproject libwebp · … → 1.3.2

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References