CVE-2020-36332: Input Validation
A flaw was found in libwebp in versions before 1.0.1 in the way it read the contents of a file without limiting memory allocation.
Reference: https://bugs.chromium.org/p/webp/issues/detail?id=391
Other sources
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-36332.
What is the severity of CVE-2020-36332?
The severity of CVE-2020-36332 is high with a severity value of 7.5.
What is the affected software for CVE-2020-36332?
The affected software for CVE-2020-36332 includes libwebp versions before 1.0.1, Mozilla Firefox ESR, Redhat Enterprise Linux, Debian Linux, and NetApp ONTAP Select Deploy administration utility.
What is the highest threat from CVE-2020-36332?
The highest threat from CVE-2020-36332 is to the service availability.
Where can I find more information about CVE-2020-36332?
You can find more information about CVE-2020-36332 at the following references: [Reference 1](https://bugzilla.redhat.com/show_bug.cgi?id=1956868), [Reference 2](https://security.netapp.com/advisory/ntap-20211104-0004/), [Reference 3](https://www.debian.org/security/2021/dsa-4930).