VDB
RHBA-2023%3A6004
RHBA-2023%3A6004
PUBLISHED
CVSS 9.600000381469727 CRITICAL
A heap-based buffer flaw was found in the way libwebp, a library used to process "WebP" image format data, processes certain specially formatted WebP images. An attacker could use this flaw to crash or execute remotely arbitrary code in an application such as a web browser compiled with this library.
Risk Scores
CVSS 3.1
9.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhel9/thunderbird-flatpak@sha256:870084c57d8583ce25c8503df6b83df2553b72b463a7be67592f4661cdafd9e7_amd64 as a component of Red Hat Enterprise Linux AppStream (v. 9) | rhel9/thunderbird-flatpak@sha256:870084c57d8583ce25c8503df6b83df2553b72b463a7be67592f4661cdafd9e7_amd64 |
Timeline
- Oct 23, 2023 CVE Published
- Nov 21, 2025 CVE Updated
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHBA-2023:6004 advisory
- https://catalog.redhat.com/software/containers/search advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhba-2023_6004.json advisory
- https://access.redhat.com/security/cve/CVE-2023-4863 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2238431 issue
- https://www.cve.org/CVERecord?id=CVE-2023-4863 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-4863 advisory
- https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_12.html advisory
- https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/ advisory
- https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/ advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog exploit