Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.4%
from disclosure to weapon4 days
Published on NVDJul 24
1st PoC+4d
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp.
Image::WebP does not link to the system libwebp. Instead, it uses a bundled copy of libwebp 0.3.0 (released 2013-03-20). That version has multiple known vulnerabilities, including CVE-2023-4863.
Any caller that decodes an untrusted WebP image reaches the bundled decoder. Because the library is compiled into the module, upgrading the system libwebp does not remediate this.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
ZAPAD · Image::WebPpublic PoCs found — 1
githubgithub.com/extratao/Image-WebP★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.