A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24(). Reference: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=9123
This seems to be a duplicate of 1956917 [0] https://bugzilla.redhat.com/show_bug.cgi?id=1956917
Upstream patch: https://chromium.googlesource.com/webm/libwebp/+/95fd65070662e01cc9170c4444f5c0859a710097
In reply to comment #1: > This seems to be a duplicate of 1956917 > > [0] https://bugzilla.redhat.com/show_bug.cgi?id=1956917 Although the fix is the same, the issue seems to be in two different lines so I'd keep them separated to avoid possible confusions to others.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4231 https://access.redhat.com/errata/RHSA-2021:4231
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-25012