A flaw was found in libwebp in versions before 1.0.1. An unitialized variable is used in function ReadSymbol. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
References
| Link | Resource |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=1956927 | Issue Tracking Patch Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2021/06/msg00005.html | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2021/06/msg00006.html | Mailing List Third Party Advisory |
| https://www.debian.org/security/2021/dsa-4930 | Third Party Advisory |
| https://support.apple.com/kb/HT212601 | Third Party Advisory |
| http://seclists.org/fulldisclosure/2021/Jul/54 | Mailing List Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20211104-0004/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Information
Published : 2021-05-21 17:15
Updated : 2021-11-30 22:00
NVD link : CVE-2018-25014
Mitre link : CVE-2018-25014
JSON object : View
Products Affected
debian
- debian_linux
apple
- ipados
- iphone_os
webmproject
- libwebp
netapp
- ontap_select_deploy_administration_utility
redhat
- enterprise_linux
CWE
CWE-908
Use of Uninitialized Resource
