{"id":"GHSA-f9pm-4g9p-6vm3","summary":"Bundled libwebp in pywebp vulnerable","details":"### Impact\npywebp versions before v0.3.0 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. The vulnerability was a heap buffer overflow which allowed a remote attacker to perform an out of bounds memory write.\n\n### Patches\nThe problem has been patched upstream in libwebp 1.3.2.\npywebp was updated to bundle a patched version of libwebp in v0.3.0.\n\n### Workarounds\nNo known workarounds without upgrading.\n\n### References\n- https://www.rezilion.com/blog/rezilion-researchers-uncover-new-details-on-severity-of-google-chrome-zero-day-vulnerability-cve-2023-4863/\n- https://nvd.nist.gov/vuln/detail/CVE-2023-4863\n","modified":"2024-12-01T05:53:36.965093Z","published":"2023-10-06T16:59:22Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-10-06T16:59:22Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/anibali/pywebp/security/advisories/GHSA-f9pm-4g9p-6vm3"},{"type":"WEB","url":"https://github.com/anibali/pywebp/commit/1f938731a158a6584977cec2cce21b21c15f6c4b"},{"type":"PACKAGE","url":"https://github.com/anibali/pywebp"}],"affected":[{"package":{"name":"webp","ecosystem":"PyPI","purl":"pkg:pypi/webp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.0"}]}],"versions":["0.1.0","0.1.0a10","0.1.0a11","0.1.0a12","0.1.0a13","0.1.0a14","0.1.0a15","0.1.0a16","0.1.0a4","0.1.0a5","0.1.0a6","0.1.0a7","0.1.0a9","0.1.1","0.1.2","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/10/GHSA-f9pm-4g9p-6vm3/GHSA-f9pm-4g9p-6vm3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}