Bugzilla – Bug 1186250
VUL-0: CVE-2018-25014: libwebp: use of uninitialized value in ReadSymbol()
Last modified: 2021-06-03 15:26:46 UTC
mgorse@suse.com A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ReadSymbol(). Reference: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9496 References: https://bugzilla.redhat.com/show_bug.cgi?id=1956927 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-25014
Affected packages: - SUSE:SLE-12-SP1:Update/libwebp 0.4.3 - SUSE:SLE-15:Update/libwebp 0.5.0 Upstream patch [0]. [0] https://chromium.googlesource.com/webm/libwebp/+log/78ad57a36ad69a9c22874b182d49d64125c380f2..907208f97ead639bd521cf355a2f203f462eade6?pretty=fuller&n=10000