{"id":7130,"date":"2023-09-28T04:45:47","date_gmt":"2023-09-28T04:45:47","guid":{"rendered":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/"},"modified":"2023-09-28T04:45:47","modified_gmt":"2023-09-28T04:45:47","slug":"cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep","status":"publish","type":"post","link":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/","title":{"rendered":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)"},"content":{"rendered":"<p>What is libwebp?<\/p>\n<p>Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services.<\/p>\n<p>What is the Attack?<\/p>\n<p>CVE-2023-5129 is a heap buffer overflow vulnerability that affects libwebp. Successful exploitation of the vulnerability can result in remote code execution or cause a denial-of-service (DoS) condition.<\/p>\n<p>Google initially identified this as a Chrome vulnerability and assigned it CVE-2023-4863. It turns out that the vulnerability affects the libwebp library, which has broader impact beyond Chrome. This prompted Google to assign a new CVE (CVE-2023-5129) to the vulnerability. The CVSS score has also been raised accordingly from 8.8 to 10.<\/p>\n<p>Why is this Significant?<\/p>\n<p>This is significant because the vulnerability affects widely used libwebp library and is being exploited in the wild, which means that a large number of users could be potentially affected. CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog on September 13th, 2023. As such, patches should be applied as soon as they become available.<\/p>\n<p>What is the Vendor Solution?<\/p>\n<p>Although Google released a patch for Chrome on September 11, 2023, each software application that employs libwebp need to distribute its own update. As such, it&#8217;s important to keep all software up to date.<\/p>\n<p>What FortiGuard Coverage is available?<\/p>\n<p>FortiGuard Labs is currently investigating coverage feasibility and will update this Threat Signal once relevant information becomes available.<a href=\"https:\/\/fortiguard.fortinet.com\/threat-signal-report\/5260\" target=\"_blank\" class=\"feedzy-rss-link-icon\" rel=\"noopener\">Read More<\/a>\u00a0<\/p>","protected":false},"excerpt":{"rendered":"<p>What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129 [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7130","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.8 - aioseo.com -->\n\t<meta name=\"description\" content=\"What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.8\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Sekuritas IT \u203a Creative solutions to unique challenges.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \u203a Sekuritas IT\" \/>\n\t\t<meta property=\"og:description\" content=\"What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2023-09-28T04:45:47+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2023-09-28T04:45:47+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/profile.php?id=100086973577423\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \u203a Sekuritas IT\" \/>\n\t\t<meta name=\"twitter:description\" content=\"What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/#blogposting\",\"name\":\"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \\u203a Sekuritas IT\",\"headline\":\"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)\",\"author\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\"},\"datePublished\":\"2023-09-28T04:45:47+00:00\",\"dateModified\":\"2023-09-28T04:45:47+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/#webpage\"},\"articleSection\":\"Uncategorized\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sekuritasit.com\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"position\":2,\"name\":\"Uncategorized\",\"item\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/#listItem\",\"name\":\"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/#listItem\",\"position\":3,\"name\":\"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/category\\\/uncategorized\\\/#listItem\",\"name\":\"Uncategorized\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\",\"name\":\"Sekuritas IT\",\"description\":\"Creative solutions to unique challenges.\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/\",\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/profile.php?id=100086973577423\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/#webpage\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/\",\"name\":\"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \\u203a Sekuritas IT\",\"description\":\"What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/2023\\\/09\\\/28\\\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/index.php\\\/author\\\/#author\"},\"datePublished\":\"2023-09-28T04:45:47+00:00\",\"dateModified\":\"2023-09-28T04:45:47+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#website\",\"url\":\"https:\\\/\\\/sekuritasit.com\\\/\",\"name\":\"Sekuritas IT\",\"alternateName\":\"Sekuritas\",\"description\":\"Creative solutions to unique challenges.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/sekuritasit.com\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \u203a Sekuritas IT","description":"What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129","canonical_url":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/#blogposting","name":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \u203a Sekuritas IT","headline":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)","author":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"publisher":{"@id":"https:\/\/sekuritasit.com\/#organization"},"datePublished":"2023-09-28T04:45:47+00:00","dateModified":"2023-09-28T04:45:47+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/#webpage"},"isPartOf":{"@id":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/#webpage"},"articleSection":"Uncategorized"},{"@type":"BreadcrumbList","@id":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/sekuritasit.com#listItem","position":1,"name":"Home","item":"https:\/\/sekuritasit.com","nextItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","name":"Uncategorized"}},{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","position":2,"name":"Uncategorized","item":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/","nextItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/#listItem","name":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)"},"previousItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/#listItem","position":3,"name":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)","previousItem":{"@type":"ListItem","@id":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/#listItem","name":"Uncategorized"}}]},{"@type":"Organization","@id":"https:\/\/sekuritasit.com\/#organization","name":"Sekuritas IT","description":"Creative solutions to unique challenges.","url":"https:\/\/sekuritasit.com\/","sameAs":["https:\/\/www.facebook.com\/profile.php?id=100086973577423"]},{"@type":"WebPage","@id":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/#webpage","url":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/","name":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \u203a Sekuritas IT","description":"What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/sekuritasit.com\/#website"},"breadcrumb":{"@id":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/#breadcrumblist"},"author":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"creator":{"@id":"https:\/\/sekuritasit.com\/index.php\/author\/#author"},"datePublished":"2023-09-28T04:45:47+00:00","dateModified":"2023-09-28T04:45:47+00:00"},{"@type":"WebSite","@id":"https:\/\/sekuritasit.com\/#website","url":"https:\/\/sekuritasit.com\/","name":"Sekuritas IT","alternateName":"Sekuritas","description":"Creative solutions to unique challenges.","inLanguage":"en-US","publisher":{"@id":"https:\/\/sekuritasit.com\/#organization"}}]},"og:locale":"en_US","og:site_name":"Sekuritas IT \u203a Creative solutions to unique challenges.","og:type":"article","og:title":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \u203a Sekuritas IT","og:description":"What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129","og:url":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/","article:published_time":"2023-09-28T04:45:47+00:00","article:modified_time":"2023-09-28T04:45:47+00:00","article:publisher":"https:\/\/www.facebook.com\/profile.php?id=100086973577423","twitter:card":"summary_large_image","twitter:title":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep) \u203a Sekuritas IT","twitter:description":"What is libwebp? Libwebp is an open-source library developed by Google for encoding and decoding images in the Webp format. Libwebp is used by various software applications, inlcuding web browsers (i.e. Chrome, Microsoft Edge, Safari, and Mozilla Firefox), image editors, Content Delivery Networks (CDNs), and various website and online services. What is the Attack? CVE-2023-5129"},"aioseo_meta_data":{"post_id":"7130","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2023-09-28 08:34:16","updated":"2025-10-15 04:43:32","seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sekuritasit.com\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/\" title=\"Uncategorized\">Uncategorized<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tCVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/sekuritasit.com"},{"label":"Uncategorized","link":"https:\/\/sekuritasit.com\/index.php\/category\/uncategorized\/"},{"label":"CVE-2023-5129 (Heap Buffer Overflow vulnerability in libwep)","link":"https:\/\/sekuritasit.com\/index.php\/2023\/09\/28\/cve-2023-5129-heap-buffer-overflow-vulnerability-in-libwep\/"}],"_links":{"self":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts\/7130","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/comments?post=7130"}],"version-history":[{"count":0,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/posts\/7130\/revisions"}],"wp:attachment":[{"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/media?parent=7130"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/categories?post=7130"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sekuritasit.com\/index.php\/wp-json\/wp\/v2\/tags?post=7130"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}