Vulnerability Name:

CVE-2020-36330 (CCN-202251)

Assigned:2020-02-25
Published:2020-02-25
Updated:2021-11-30
Summary:A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.
CVSS v3 Severity:9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): High
9.1 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
7.9 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): High
9.1 Critical (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H)
7.9 High (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
9.4 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-125
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2020-36330

Source: FULLDISC
Type: Mailing List, Third Party Advisory
20210723 APPLE-SA-2021-07-21-1 iOS 14.7 and iPadOS 14.7

Source: CCN
Type: Red Hat Bugzilla - Bug 1956853
(CVE-2020-36330) - CVE-2020-36330 libwebp: out-of-bounds read in ChunkVerifyAndAssign() in mux/muxread.c

Source: MISC
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1956853

Source: CCN
Type: libwebp Google GIT Repository
chromium / webm / libwebp / 1344a2e947c749d231141a295327e5b99b444d63

Source: XF
Type: UNKNOWN
libwebp-cve202036330-dos(202251)

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210605 [SECURITY] [DLA 2672-1] libwebp security update

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20210606 [SECURITY] [DLA 2677-1] libwebp security update

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20211104-0004/

Source: CONFIRM
Type: Not Applicable
https://support.apple.com/kb/HT212601

Source: DEBIAN
Type: Third Party Advisory
DSA-4930

Source: CCN
Type: IBM Security Bulletin 6551876 (Cloud Pak for Security)
Cloud Pak for Security uses packages that are vulnerable to multiple CVEs

Vulnerable Configuration:Configuration 1:
  • cpe:/a:webmproject:libwebp:*:*:*:*:*:*:*:* (Version < 1.0.1)

  • Configuration 2:
  • cpe:/o:debian:debian_linux:9.0:*:*:*:*:*:*:*
  • OR cpe:/o:debian:debian_linux:10.0:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:apple:ipados:*:*:*:*:*:*:*:* (Version < 14.7)
  • OR cpe:/o:apple:iphone_os:*:*:*:*:*:*:*:* (Version < 14.7)

  • Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:webmproject:libwebp:1.0.0:*:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:cloud_pak_for_security:1.7.2.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:7469
    P
    cpp7-7.5.0+r278197-4.30.1 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:51569
    P
    Security update for libarchive (Low)
    2022-11-23
    oval:org.opensuse.security:def:95270
    P
    Security update for ceph (Important) (in QA)
    2022-07-15
    oval:org.opensuse.security:def:3587
    P
    libecpg6-10.10-1.15.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:95217
    P
    libwebp6-0.5.0-3.5.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:6040
    P
    Security update for e2fsprogs (Important)
    2022-05-17
    oval:org.opensuse.security:def:101983
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP3) (Important)
    2022-04-25
    oval:org.opensuse.security:def:99468
    P
    (Important)
    2022-04-11
    oval:com.redhat.rhsa:def:20214231
    P
    RHSA-2021:4231: libwebp security update (Moderate)
    2021-11-09
    oval:org.opensuse.security:def:97033
    P
    rarpd-s20161105-6.10 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:99667
    P
    (Important)
    2021-08-16
    oval:org.opensuse.security:def:99975
    P
    (Moderate)
    2021-07-20
    oval:org.opensuse.security:def:111567
    P
    Security update for libwebp (Critical)
    2021-07-10
    oval:org.opensuse.security:def:7425
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:69858
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:99269
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:10678
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:93069
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:8967
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:70818
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:68558
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:109229
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:96305
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:10091
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92518
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:1468
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:70231
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:66811
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:75879
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:93222
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:118314
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:9337
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:91933
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:102563
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:5722
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:69477
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:98883
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:109643
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:10269
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92717
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:8594
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:70409
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:67129
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:76197
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:119783
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:9519
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92128
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:102977
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:69659
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:99078
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:10643
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92916
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:8772
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:70783
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:68514
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:108649
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:95850
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:9718
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:92319
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:102315
    P
    Security update for libwebp (Critical)
    2021-06-04
    oval:org.opensuse.security:def:32101
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:60271
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:87397
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:23910
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:56025
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:83289
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:5051
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:34448
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:89395
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:30202
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:58756
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:85646
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:51898
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:126713
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:32933
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:88127
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:26064
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:57005
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:83409
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:31182
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:59482
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:86093
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:55195
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:81079
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:127110
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:33659
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:88440
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:29372
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:57452
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:84150
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:31629
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:59740
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:86565
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:23581
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:55905
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:82579
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:33917
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:89137
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:30082
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:57924
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:84608
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:125543
    P
    Security update for libwebp (Critical)
    2021-06-02
    BACK
    webmproject libwebp *
    debian debian linux 9.0
    debian debian linux 10.0
    redhat enterprise linux 8.0
    netapp ontap select deploy administration utility -
    apple ipados *
    apple iphone os *
    webmproject libwebp 1.0.0
    ibm cloud pak for security 1.7.2.0