QID 995538
Date Published: 2023-10-09
QID 995538: Python (Pip) Security Update for webp (GHSA-f9pm-4g9p-6vm3)
pywebp versions before v0.3.0 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-4863. The vulnerability was a heap buffer overflow which allowed a remote attacker to perform an out of bounds memory write.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-f9pm-4g9p-6vm3 for updates and patch information.
Vendor References
- GHSA-f9pm-4g9p-6vm3 -
github.com/advisories/GHSA-f9pm-4g9p-6vm3
CVEs related to QID 995538
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f9pm-4g9p-6vm3 | webp |
|