Umbra Wiki cve cve/CVE-2023-5217
Back to wiki

CVE-2023-5217 — Google Chromium libvpx Heap Buffer Overflow Vulnerability

provenance: imported · CVE: CVE-2023-5217

CVE-2023-5217: Google Chromium libvpx Heap Buffer Overflow Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Google
Product Chromium libvpx
Date added 2023-10-02
Due date 2023-10-23
Ransomware campaign use Unknown

Description

Google Chromium libvpx contains a heap buffer overflow vulnerability in vp8 encoding that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could impact web browsers using libvpx, including but not limited to Google Chrome.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html; https://nvd.nist.gov/vuln/detail/CVE-2023-5217

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-5217
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog