CVE-2018-25010
Description
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A heap-based buffer overflow in libwebp before 1.0.1 allows an out-of-bounds read via a crafted image in ApplyFilter().
Vulnerability
The vulnerability is a heap-based buffer overflow in the ApplyFilter() function in src/utils/quant_levels_dec_utils.c of libwebp, a library for encoding and decoding WebP images. The bug was introduced before version 1.0.1 and allows an out-of-bounds read when processing a crafted lossless WebP image with specific filter parameters. The issue is triggered when the filtering radius exceeds the image dimensions, causing an out-of-bounds access on the heap [1][2].
Exploitation
An attacker would need to craft a malicious lossless WebP image that sets the alpha filtering radius to a value larger than the image width or height. When a user or application using libwebp decodes this image, the ApplyFilter() function is called with the oversized radius, leading to a heap out-of-bounds read. The fix limits the radius to the minimum of the image width and height to prevent the condition [2].
Impact
Successful exploitation could lead to an out-of-bounds read of heap memory, potentially resulting in information disclosure. The vulnerability has a CVSS score of 5.5 (medium severity) and could be used to leak sensitive data or cause a crash (denial of service) [1]. No remote code execution has been demonstrated for this specific issue.
Mitigation
The vulnerability is fixed in libwebp version 1.0.1, which was released on 2018-06-29. Users should update libwebp to version 1.0.1 or later. The fix was committed in commit 1344a2e947c749d231141a295327e5b99b444d63. Distributions such as Red Hat have issued advisories and updated packages [1][2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
37- libwebp/libwebpdescription
- Range: <1.0.1
- osv-coords35 versionspkg:rpm/almalinux/libwebppkg:rpm/almalinux/libwebp-develpkg:rpm/opensuse/libwebp&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/libwebp&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/libwebp&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3pkg:rpm/suse/libwebp&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/libwebp&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/libwebp&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 1.0.0-5.el8+ 34 more
- (no CPE)range: < 1.0.0-5.el8
- (no CPE)range: < 1.0.0-5.el8
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- bugs.chromium.org/p/oss-fuzz/issues/detailmitrex_refsource_MISC
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_MISC
- chromium.googlesource.com/webm/libwebp/+/1344a2e947c749d231141a295327e5b99b444d63mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.