VDB
RHBA-2023%3A5988
RHBA-2023%3A5988
PUBLISHED
CVSS 9.600000381469727 CRITICAL
A heap-based buffer flaw was found in the way libwebp, a library used to process "WebP" image format data, processes certain specially formatted WebP images. An attacker could use this flaw to crash or execute remotely arbitrary code in an application such as a web browser compiled with this library.
Risk Scores
CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhel9/firefox-flatpak@sha256:ef71228c905275b0c973e231942a1949b2036217cf0ed7e671ea1a9dded66fbd_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | * |
Timeline
- Oct 23, 2023 CVE Published
- Nov 21, 2025 CVE Updated
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHBA-2023:5988 advisory
- https://catalog.redhat.com/software/containers/search advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhba-2023_5988.json advisory
- https://access.redhat.com/security/cve/CVE-2023-4863 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2238431 issue
- https://www.cve.org/CVERecord?id=CVE-2023-4863 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863 advisory
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html advisory
- https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/ advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit