CVSS Score v3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.0053
67.5th percentile
Risk Priority
20
60% EPSS · 20% KEV · 20% CVSS
Summary
CVE-2020-36328 is a critical-severity Out-of-bounds Write (CWE-787) vulnerability in Redhat Enterprise Linux . Its CVSS base score is 9.8 (Critical).
Operationally, ranked in the top 32.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
Vulnerability
Related Threats
Affected Assets
Mitigating Controls
Vulnerability details
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as…
more well as system availability.
CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
webmproject
libwebp
≤ 1.0.1
redhat
enterprise linux
7.0, 8.0
netapp
ontap select deploy administration utility
all versions
debian
debian linux
10.0, 9.0
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Out-of-bounds writes that corrupt control flow or inject shellcode are rendered non-executable by the same memory protections.
References
Mailing List, Third Party Advisory · secalert@redhat.com
Issue Tracking, Patch, Release Notes, Third Party Advisory · secalert@redhat.com
Mailing List, Third Party Advisory · secalert@redhat.com
Mailing List, Third Party Advisory · secalert@redhat.com
Third Party Advisory · secalert@redhat.com
Third Party Advisory · secalert@redhat.com
Third Party Advisory · secalert@redhat.com
Mailing List, Third Party Advisory · af854a3a-2127-422b-91ae-364da2661108
Issue Tracking, Patch, Release Notes, Third Party Advisory · af854a3a-2127-422b-91ae-364da2661108
Mailing List, Third Party Advisory · af854a3a-2127-422b-91ae-364da2661108
Mailing List, Third Party Advisory · af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory · af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory · af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory · af854a3a-2127-422b-91ae-364da2661108