AlmaLinux 2237 Published by

A libwebp security update has been released for AlmaLinux.



ALSA-2021:2354 Important: libwebp security update


Type:
security

Severity:
important

Release date:
2021-06-08

Description
Security Fix(es):
* libwebp: heap-based buffer overflow in PutLE16() (CVE-2018-25011)
* libwebp: heap-based buffer overflow in WebPDecode*Into functions (CVE-2020-36328)
* libwebp: use-after-free in EmitFancyRGB() in dec/io_dec.c (CVE-2020-36329)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References:
CVE-2018-25011
CVE-2020-36328
CVE-2020-36329

Updates packages:
libwebp-1.0.0-3.el8_4.i686.rpm
libwebp-1.0.0-3.el8_4.x86_64.rpm
libwebp-devel-1.0.0-3.el8_4.i686.rpm
libwebp-devel-1.0.0-3.el8_4.x86_64.rpm

Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

  ALSA-2021:2354 Important: libwebp security update