Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Project Subscriptions

Vendors Products
Iphone Os Subscribe
Debian Linux Subscribe
Fedoraproject Subscribe
Microsoft Subscribe
Edge Chromium Subscribe
Mozilla Subscribe
Firefox Subscribe
Thunderbird Subscribe
Enterprise Linux Subscribe
Rhel Aus Subscribe
Rhel E4s Subscribe
Rhel Eus Subscribe
Rhel Tus Subscribe
Webmproject Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3591-1 firefox-esr security update
Debian DLA Debian DLA DLA-3598-1 libvpx security update
Debian DLA Debian DLA DLA-3601-1 thunderbird security update
Debian DSA Debian DSA DSA-5508-1 chromium security update
Debian DSA Debian DSA DSA-5509-1 firefox-esr security update
Debian DSA Debian DSA DSA-5510-1 libvpx security update
EUVD EUVD EUVD-2023-2578 Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Github GHSA Github GHSA GHSA-qqvq-6xgj-jw8g Electron affected by libvpx's heap buffer overflow in vp8 encoding
Ubuntu USN Ubuntu USN USN-6403-1 libvpx vulnerabilities
Ubuntu USN Ubuntu USN USN-6403-2 libvpx vulnerabilities
Ubuntu USN Ubuntu USN USN-6403-3 libvpx vulnerabilities
Ubuntu USN Ubuntu USN USN-6404-1 Firefox vulnerabilities
Ubuntu USN Ubuntu USN USN-6405-1 Thunderbird vulnerabilities
Ubuntu USN Ubuntu USN USN-7172-1 libvpx vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://seclists.org/fulldisclosure/2023/Oct/12 cve-icon cve-icon
http://seclists.org/fulldisclosure/2023/Oct/16 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/28/5 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/28/6 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/29/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/29/11 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/29/12 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/29/14 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/29/2 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/29/7 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/29/9 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/30/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/30/2 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/30/3 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/30/4 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/09/30/5 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/10/01/1 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/10/01/2 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/10/01/5 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/10/02/6 cve-icon cve-icon
http://www.openwall.com/lists/oss-security/2023/10/03/11 cve-icon cve-icon
https://arstechnica.com/security/2023/09/new-0-day-in-chrome-and-firefox-is-likely-to-plague-other-software/ cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=2241191 cve-icon cve-icon
https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_27.html cve-icon cve-icon
https://crbug.com/1486441 cve-icon cve-icon
https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590 cve-icon cve-icon
https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282 cve-icon cve-icon
https://github.com/webmproject/libvpx/releases/tag/v1.13.1 cve-icon cve-icon
https://github.com/webmproject/libvpx/tags cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2023/09/msg00038.html cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2023/10/msg00001.html cve-icon cve-icon
https://lists.debian.org/debian-lts-announce/2023/10/msg00015.html cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4MFWDFJSSIFKWKNOCTQCFUNZWAXUCSS4/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/55YVCZNAVY3Y5E4DWPWMX2SPKZ2E5SOV/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AY642Z6JZODQJE7Z62CFREVUHEGCXGPD/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BCVSHVX2RFBU3RMCUFSATVQEJUFD4Q63/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CWEJYS5NC7KVFYU3OAMPKQDYN6JQGVK6/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TE7F54W5O5RS4ZMAAC7YK3CZWQXIDSKB/ cve-icon cve-icon
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I/ cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2023-5217 cve-icon
https://pastebin.com/TdkC4pDv cve-icon cve-icon
https://security-tracker.debian.org/tracker/CVE-2023-5217 cve-icon cve-icon
https://security.gentoo.org/glsa/202310-04 cve-icon cve-icon
https://security.gentoo.org/glsa/202401-34 cve-icon cve-icon
https://stackdiary.com/google-discloses-a-webm-vp8-bug-tracked-as-cve-2023-5217/ cve-icon cve-icon
https://support.apple.com/kb/HT213961 cve-icon cve-icon
https://support.apple.com/kb/HT213972 cve-icon cve-icon
https://twitter.com/maddiestone/status/1707163313711497266 cve-icon cve-icon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog cve-icon
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-5217 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2023-5217 cve-icon
https://www.debian.org/security/2023/dsa-5508 cve-icon cve-icon
https://www.debian.org/security/2023/dsa-5509 cve-icon cve-icon
https://www.debian.org/security/2023/dsa-5510 cve-icon cve-icon
https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/ cve-icon cve-icon cve-icon
https://www.openwall.com/lists/oss-security/2023/09/28/5 cve-icon cve-icon
History

Tue, 21 Oct 2025 23:15:00 +0000


Tue, 21 Oct 2025 20:30:00 +0000


Tue, 21 Oct 2025 19:30:00 +0000


Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.0203}

epss

{'score': 0.01679}


Thu, 03 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple ipados
CPEs cpe:2.3:o:apple:ipad_os:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipad_os:16.7:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:ipados:16.7:*:*:*:*:*:*:*
Vendors & Products Apple ipad Os
Apple ipados

Mon, 03 Feb 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2023-10-02'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 20 Dec 2024 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:firefox_focus:*:*:*:*:*:android:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:-:*:*:*
cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Mozilla firefox Esr
Mozilla firefox Focus

Wed, 14 Aug 2024 01:00:00 +0000

Type Values Removed Values Added
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2025-10-21T23:05:36.191Z

Reserved: 2023-09-27T01:52:05.679Z

Link: CVE-2023-5217

cve-icon Vulnrichment

Updated: 2024-08-02T07:52:08.351Z

cve-icon NVD

Status : Analyzed

Published: 2023-09-28T16:15:10.980

Modified: 2025-10-24T14:07:24.923

Link: CVE-2023-5217

cve-icon Redhat

Severity : Important

Publid Date: 2023-09-27T00:00:00Z

Links: CVE-2023-5217 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses