First published: Wed Sep 27 2023(Updated: )
### Impact Heap buffer overflow in `libwebp` allows a remote attacker to perform an out of bounds memory write via a crafted webp image. ### References - https://github.com/advisories/GHSA-j7hp-h8jx-5ppr - https://blog.isosceles.com/the-webp-0day/
Affected Software | Affected Version | How to fix |
---|---|---|
npm/@napi-rs/image | <1.7.0 | 1.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
GHSA-4vjr-crvh-383h allows a remote attacker to perform an out of bounds memory write via a crafted webp image.
GHSA-4vjr-crvh-383h can be exploited by sending a crafted webp image to the vulnerable application.
The severity of GHSA-4vjr-crvh-383h is high with a CVSS score of 8.8.
Yes, updating to version 1.7.0 of the @napi-rs/image package will fix GHSA-4vjr-crvh-383h.
For more information about GHSA-4vjr-crvh-383h, you can refer to the GitHub advisory and commit links provided.