
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2018-25012 is a security vulnerability discovered in libwebp versions before 1.0.1, specifically affecting the GetLE24() function. The vulnerability was identified as a heap-based buffer overflow issue that impacts the WebP image format processing library (Debian Security).
The vulnerability is characterized as an out-of-bounds read in WebPMuxCreateInternal() function. The issue arose from insufficient size checking before parsing VP8X chunk data, which could lead to buffer overflow conditions (Red Hat Bugzilla). The vulnerability was discovered through the OSS-Fuzz project and was assigned bug ID 9123 (OSS-Fuzz).
If exploited, this vulnerability could allow an attacker to cause the application to crash, resulting in a denial of service condition. Additionally, if a user or automated system were tricked into opening a specially crafted image file, it could potentially lead to arbitrary code execution (Ubuntu Security).
The vulnerability requires a specially crafted WebP image file to be processed by the affected library. An attacker would need to convince a user or automated system to process a malicious image file to exploit this vulnerability (Red Hat Security).
The vulnerability was fixed in libwebp version 1.0.1. The fix was implemented through a patch that adds proper size checking before parsing VP8X data (Chromium Source). Users are advised to upgrade to version 1.0.1 or later to address this security issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."