ELA-423-1 libwebp security update

buffer overflows

2021-05-09
Packagelibwebp
Version0.4.1-1.2+deb8u1
Related CVEs CVE-2018-25009 CVE-2018-25010 CVE-2018-25011 CVE-2018-25012 CVE-2018-25013 CVE-2018-25014 CVE-2020-36328 CVE-2020-36329 CVE-2020-36330 CVE-2020-36331


Several security vulnerabilities were discovered in libwebp, a lossy compression library for digital photographic images. Heap-based buffer overflows may lead to a denial-of-service or potentially the execution of arbitrary code.



For Debian 8 jessie, these problems have been fixed in version 0.4.1-1.2+deb8u1.

We recommend that you upgrade your libwebp packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.