Vulnerability Name:

CVE-2018-25011 (CCN-202259)

Assigned:2018-07-30
Published:2018-07-30
Updated:2023-02-10
Summary:A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
9.8 Critical (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
10.0 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-787
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2018-25011

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla - Bug 1956919
(CVE-2018-25011) - CVE-2018-25011 libwebp: heap-based buffer overflow in PutLE16()

Source: secalert@redhat.com
Type: Issue Tracking, Patch, Release Notes, Third Party Advisory
secalert@redhat.com

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: libwebp Google GIT Repository
chromium / webm / libwebp / be738c6d396fa5a272c1b209be4379a7532debfe..29fb8562c60b5a919a75d904ff7366af423f8ab9

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
libwebp-cve201825011-bo(202259)

Source: CCN
Type: IBM Security Bulletin 6493729 (Cloud Pak for Security)
Cloud Pak for Security is vulnerable to several CVEs

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*
  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*
  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*
  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*
  • Configuration RedHat 6:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 7:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:webmproject:libwebp:1.0.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:cloud_pak_for_security:1.7.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:cloud_pak_for_security:1.7.2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7469
    P
    cpp7-7.5.0+r278197-4.30.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51569
    P
    Security update for libarchive (Low)
    2022-11-23
    oval:org.opensuse.security:def:95270
    P
    Security update for ceph (Important) (in QA)
    2022-07-15
    oval:org.opensuse.security:def:3587
    P
    libecpg6-10.10-1.15.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95217
    P
    libwebp6-0.5.0-3.5.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:6040
    P
    Security update for e2fsprogs (Important)
    2022-05-17
    oval:org.opensuse.security:def:101983
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important)
    2022-04-25
    oval:org.opensuse.security:def:99468
    P
    (Important)
    2022-04-11
    oval:org.opensuse.security:def:97033
    P
    rarpd-s20161105-6.10 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:99667
    P
    (Important)
    2021-08-16
    oval:org.opensuse.security:def:99975
    P
    (Moderate)
    2021-07-20
    oval:org.opensuse.security:def:111567
    P
    Security update for libwebp (Critical)
    2021-07-10
    oval:com.redhat.rhsa:def:20212354
    P
    RHSA-2021:2354: libwebp security update (Important)
    2021-06-09
    oval:com.redhat.rhsa:def:20212328
    P
    RHSA-2021:2328: qt5-qtimageformats security update (Important)
    2021-06-08
    oval:com.redhat.rhsa:def:20212260
    P
    RHSA-2021:2260: libwebp security update (Important)
    2021-06-07
    oval:org.opensuse.security:def:5722
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:69477
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:98883
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:109643
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:10269
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92717
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:8594
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:70409
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:67129
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:76197
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:119783
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:9519
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92128
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:102977
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:69659
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:99078
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:10643
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92916
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:8772
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:70783
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:68514
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:108649
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:95850
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:9718
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92319
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:102315
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:7425
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:69858
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:99269
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:10678
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:93069
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:8967
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:70818
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:68558
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:109229
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:96305
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:10091
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92518
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:1468
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:70231
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:66811
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:75879
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:93222
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:118314
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:9337
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:91933
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:102563
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:31182
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:59482
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:86093
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:55195
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:81079
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:127110
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:33659
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:88440
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:29372
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:57452
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:84150
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:31629
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:59740
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:86565
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:23581
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:55905
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:82579
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:33917
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:89137
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:30082
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:57924
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:84608
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:125543
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:32101
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:60271
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:87397
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:23910
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:56025
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:83289
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:5051
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:34448
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:89395
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:30202
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:58756
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:85646
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:51898
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:126713
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:32933
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:88127
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:26064
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:57005
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:83409
    P
    Security update for libwebp (Critical)
    2021-06-02
    BACK
    webmproject libwebp 1.0.0
    ibm cloud pak for security 1.7.0.0
    ibm cloud pak for security 1.7.1.0
    ibm cloud pak for security 1.7.2.0