CVE-2016-9085: Integer Overflow
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
Other sources
Multiple integer overflows were found in libwebp library.
Upstream patch:
https://chromium.googlesource.com/webm/libwebp/+/e2affacc35f1df6cc3b1a9fa0ceff5ce2d0cce83
CVE assignment:
http://seclists.org/oss-sec/2016/q4/253
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9085?
The severity of CVE-2016-9085 is rated as high due to the potential for attackers to exploit multiple integer overflows.
How do I fix CVE-2016-9085?
To fix CVE-2016-9085, upgrade the libwebp library to version 0.5.2 or later.
What systems are affected by CVE-2016-9085?
CVE-2016-9085 affects libwebp versions up to 0.5.2 and is present in Fedora versions 24 and 25.
What types of vulnerabilities does CVE-2016-9085 represent?
CVE-2016-9085 represents vulnerabilities related to integer overflows within the libwebp library.
Who should be concerned about CVE-2016-9085?
Developers and administrators using affected versions of the libwebp library should be concerned about CVE-2016-9085.