Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "117.0.5938.132"
}
]
},
{
"cpe": "cpe:2.3:a:microsoft:edge:116.0.1938.98:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "116.0.1938.98"
}
]
},
{
"cpe": "cpe:2.3:a:microsoft:edge:117.0.2045.47:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "117.0.2045.47"
}
]
},
{
"cpe": "cpe:2.3:a:microsoft:edge_chromium:116.0.5845.229:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "116.0.5845.229"
}
]
},
{
"cpe": "cpe:2.3:a:microsoft:edge_chromium:117.0.5938.132:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "117.0.5938.132"
}
]
},
{
"cpe": "cpe:2.3:a:mozilla:firefox:*:*:*:*:*:android:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "118.1"
}
]
},
{
"cpe": "cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "118.0.1"
}
]
},
{
"cpe": "cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "115.3.1"
}
]
},
{
"cpe": "cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "115.3.1"
}
]
},
{
"cpe": "cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "17.0"
},
{
"fixed": "17.0.3"
}
]
},
{
"cpe": "cpe:2.3:o:apple:ipados:16.7:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "16.7"
}
]
},
{
"cpe": "cpe:2.3:o:apple:iphone_os:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "17.0"
},
{
"fixed": "17.0.3"
}
]
},
{
"cpe": "cpe:2.3:o:apple:iphone_os:16.7:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "16.7"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "10.0"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.0"
}
]
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "37"
}
]
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "38"
}
]
},
{
"cpe": "cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "39"
}
]
},
{
"cpe": "cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.0"
}
]
}
]
}{
"cpe": "cpe:2.3:a:webmproject:libvpx:*:*:*:*:*:*:*:*",
"source": [
"CPE_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.13.1"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-5217.json"
"2026-04-12T08:24:35Z"
[
{
"signature_type": "Function",
"id": "CVE-2023-5217-59c4ee72",
"signature_version": "v1",
"digest": {
"function_hash": "100230110426315063526584035075349816268",
"length": 828.0
},
"source": "https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282",
"target": {
"file": "test/encode_api_test.cc",
"function": "TEST"
},
"deprecated": false
},
{
"signature_type": "Line",
"id": "CVE-2023-5217-b975f3f7",
"signature_version": "v1",
"digest": {
"line_hashes": [
"330207852396136827555187902995997508991",
"136729999502473988878370435018177723713",
"15678369136114235740638393954350936456",
"29923588737913573680652580060977133403",
"37773578129138277403789668865252074553",
"208095115678472981879396413634191585616",
"208615308191935464082942480319992654085",
"6770653278206996996157363816394479362",
"300357361493662169961043031214313606186",
"216511662522186585972998914279732097668"
],
"threshold": 0.9
},
"source": "https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282",
"target": {
"file": "test/encode_api_test.cc"
},
"deprecated": false
},
{
"signature_type": "Line",
"id": "CVE-2023-5217-d8e47c27",
"signature_version": "v1",
"deprecated": false,
"digest": {
"line_hashes": [
"145482218640286121211368997722597947029",
"168502398490642422058993771546900085627",
"4517982599115396846171772755713147428"
],
"threshold": 0.9
},
"target": {
"file": "vp8/encoder/onyx_if.c"
},
"source": "https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590"
},
{
"signature_type": "Function",
"id": "CVE-2023-5217-ddc6739b",
"source": "https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282",
"deprecated": false,
"digest": {
"function_hash": "174559640541706553597192381471309499032",
"length": 421.0
},
"target": {
"file": "test/encode_api_test.cc",
"function": "InitCodec"
},
"signature_version": "v1"
},
{
"signature_type": "Function",
"id": "CVE-2023-5217-eb8089c4",
"source": "https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590",
"deprecated": false,
"digest": {
"function_hash": "9318311977028663908885622115267581070",
"length": 8188.0
},
"target": {
"file": "vp8/encoder/onyx_if.c",
"function": "vp8_change_config"
},
"signature_version": "v1"
}
]