{"id":"GHSA-4c29-gfrp-g6x9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-4c29-gfrp-g6x9","summary":"CefSharp affected by libvpx's heap buffer overflow in vp8 encoding","details":"Google is aware that an exploit for CVE-2023-5217 exists in the wild.\n\nDescription\nHeap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)\n\nReferences\n- https://www.cve.org/CVERecord?id=CVE-2023-5217\n- https://nvd.nist.gov/vuln/detail/CVE-2023-5217\n","published":"2023-10-05T13:22:50Z","modified":"2024-11-30T05:28:27.711681Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"CefSharp.Common","fixedVersion":"117.2.20"},{"ecosystem":"NuGet","name":"CefSharp.Common.NETCore","fixedVersion":"117.2.20"}],"fix":{"url":"https://github.com/cefsharp/CefSharp/commit/45e66f7c0f9094f2fd81ab57b37a9ed9576b51b8","label":"cefsharp/CefSharp@45e66f7"},"references":[{"type":"WEB","url":"https://github.com/cefsharp/CefSharp/security/advisories/GHSA-4c29-gfrp-g6x9"},{"type":"WEB","url":"https://github.com/cefsharp/CefSharp/commit/45e66f7c0f9094f2fd81ab57b37a9ed9576b51b8"},{"type":"PACKAGE","url":"https://github.com/cefsharp/CefSharp"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-30T05:28:27.711681Z"}}