A libwebp security update has been released for AlmaLinux.
ALSA-2021:2354 Important: libwebp security update
Type:
security
Severity:
important
Release date:
2021-06-08
Description
Security Fix(es):
* libwebp: heap-based buffer overflow in PutLE16() (CVE-2018-25011)
* libwebp: heap-based buffer overflow in WebPDecode*Into functions (CVE-2020-36328)
* libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c (CVE-2020-36329)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References:
CVE-2018-25011
CVE-2020-36328
CVE-2020-36329
Updates packages:
libwebp-1.0.0-3.el8_4.i686.rpm
libwebp-1.0.0-3.el8_4.x86_64.rpm
libwebp-devel-1.0.0-3.el8_4.i686.rpm
libwebp-devel-1.0.0-3.el8_4.x86_64.rpm
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.