A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2021-05-21T16:14:21

Updated: 2021-11-12T08:06:24

Reserved: 2021-05-04T00:00:00


Link: CVE-2020-36328

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-05-21T17:15:08.270

Modified: 2023-01-09T16:41:59.350


Link: CVE-2020-36328

JSON object: View

cve-icon Redhat Information

No data.

CWE