<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for libwebp</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2021:1860-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-07-10T18:55:42Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-07-10T18:55:42Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-07-10T18:55:42Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for libwebp</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for libwebp fixes the following issues:

- CVE-2018-25010: Fixed heap-based buffer overflow in ApplyFilter() (bsc#1185685).
- CVE-2020-36330: Fixed heap-based buffer overflow in ChunkVerifyAndAssign() (bsc#1185691).
- CVE-2020-36332: Fixed extreme memory allocation when reading a file (bsc#1185674).
- CVE-2020-36329: Fixed use-after-free in EmitFancyRGB() (bsc#1185652).
- CVE-2018-25012: Fixed heap-based buffer overflow in GetLE24() (bsc#1185690).
- CVE-2020-36328: Fixed heap-based buffer overflow in WebPDecode*Into functions (bsc#1185688).
- CVE-2018-25013: Fixed heap-based buffer overflow in ShiftBytes() (bsc#1185654).
- CVE-2020-36331: Fixed heap-based buffer overflow in ChunkAssignData() (bsc#1185686).
- CVE-2018-25009: Fixed heap-based buffer overflow in GetLE16() (bsc#1185673).
- CVE-2018-25011: Fixed fail on multiple image chunks (bsc#1186247).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-SLE-15.3-2021-1860</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      <Description>E-Mail link for openSUSE-SU-2021:1860-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185652</URL>
      <Description>SUSE Bug 1185652</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185654</URL>
      <Description>SUSE Bug 1185654</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185673</URL>
      <Description>SUSE Bug 1185673</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185674</URL>
      <Description>SUSE Bug 1185674</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185685</URL>
      <Description>SUSE Bug 1185685</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185686</URL>
      <Description>SUSE Bug 1185686</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185688</URL>
      <Description>SUSE Bug 1185688</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185690</URL>
      <Description>SUSE Bug 1185690</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185691</URL>
      <Description>SUSE Bug 1185691</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1186247</URL>
      <Description>SUSE Bug 1186247</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-25009/</URL>
      <Description>SUSE CVE CVE-2018-25009 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-25010/</URL>
      <Description>SUSE CVE CVE-2018-25010 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-25011/</URL>
      <Description>SUSE CVE CVE-2018-25011 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-25012/</URL>
      <Description>SUSE CVE CVE-2018-25012 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2018-25013/</URL>
      <Description>SUSE CVE CVE-2018-25013 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-36328/</URL>
      <Description>SUSE CVE CVE-2020-36328 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-36329/</URL>
      <Description>SUSE CVE CVE-2020-36329 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-36330/</URL>
      <Description>SUSE CVE CVE-2020-36330 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-36331/</URL>
      <Description>SUSE CVE CVE-2020-36331 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-36332/</URL>
      <Description>SUSE CVE CVE-2020-36332 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="openSUSE Leap 15.3">
      <Branch Type="Product Name" Name="openSUSE Leap 15.3">
        <FullProductName ProductID="openSUSE Leap 15.3" CPE="cpe:/o:opensuse:leap:15.3">openSUSE Leap 15.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="libwebp6-0.5.0-3.5.1">
      <FullProductName ProductID="libwebp6-0.5.0-3.5.1">libwebp6-0.5.0-3.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebp6-32bit-0.5.0-3.5.1">
      <FullProductName ProductID="libwebp6-32bit-0.5.0-3.5.1">libwebp6-32bit-0.5.0-3.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebpdecoder2-0.5.0-3.5.1">
      <FullProductName ProductID="libwebpdecoder2-0.5.0-3.5.1">libwebpdecoder2-0.5.0-3.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebpdecoder2-32bit-0.5.0-3.5.1">
      <FullProductName ProductID="libwebpdecoder2-32bit-0.5.0-3.5.1">libwebpdecoder2-32bit-0.5.0-3.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebpextras0-0.5.0-3.5.1">
      <FullProductName ProductID="libwebpextras0-0.5.0-3.5.1">libwebpextras0-0.5.0-3.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebpextras0-32bit-0.5.0-3.5.1">
      <FullProductName ProductID="libwebpextras0-32bit-0.5.0-3.5.1">libwebpextras0-32bit-0.5.0-3.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebpmux2-0.5.0-3.5.1">
      <FullProductName ProductID="libwebpmux2-0.5.0-3.5.1">libwebpmux2-0.5.0-3.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="libwebpmux2-32bit-0.5.0-3.5.1">
      <FullProductName ProductID="libwebpmux2-32bit-0.5.0-3.5.1">libwebpmux2-32bit-0.5.0-3.5.1</FullProductName>
    </Branch>
    <Relationship ProductReference="libwebp6-0.5.0-3.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1">libwebp6-0.5.0-3.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebp6-32bit-0.5.0-3.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1">libwebp6-32bit-0.5.0-3.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebpdecoder2-0.5.0-3.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1">libwebpdecoder2-0.5.0-3.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebpdecoder2-32bit-0.5.0-3.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1">libwebpdecoder2-32bit-0.5.0-3.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebpextras0-0.5.0-3.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1">libwebpextras0-0.5.0-3.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebpextras0-32bit-0.5.0-3.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1">libwebpextras0-32bit-0.5.0-3.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebpmux2-0.5.0-3.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1">libwebpmux2-0.5.0-3.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="libwebpmux2-32bit-0.5.0-3.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1">libwebpmux2-32bit-0.5.0-3.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE16().</Note>
    </Notes>
    <CVE>CVE-2018-25009</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.1</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-25009.html</URL>
        <Description>CVE-2018-25009</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185673</URL>
        <Description>SUSE Bug 1185673</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ApplyFilter().</Note>
    </Notes>
    <CVE>CVE-2018-25010</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.1</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-25010.html</URL>
        <Description>CVE-2018-25010</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185685</URL>
        <Description>SUSE Bug 1185685</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().</Note>
    </Notes>
    <CVE>CVE-2018-25011</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>7.5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-25011.html</URL>
        <Description>CVE-2018-25011</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1186247</URL>
        <Description>SUSE Bug 1186247</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().</Note>
    </Notes>
    <CVE>CVE-2018-25012</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.1</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-25012.html</URL>
        <Description>CVE-2018-25012</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185690</URL>
        <Description>SUSE Bug 1185690</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in ShiftBytes().</Note>
    </Notes>
    <CVE>CVE-2018-25013</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.1</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2018-25013.html</URL>
        <Description>CVE-2018-25013</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185654</URL>
        <Description>SUSE Bug 1185654</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2020-36328</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>7.5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-36328.html</URL>
        <Description>CVE-2020-36328</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185688</URL>
        <Description>SUSE Bug 1185688</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in libwebp in versions before 1.0.1. A use-after-free was found due to a thread being killed too early. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.</Note>
    </Notes>
    <CVE>CVE-2020-36329</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>7.5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>6.7</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-36329.html</URL>
        <Description>CVE-2020-36329</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185652</URL>
        <Description>SUSE Bug 1185652</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1187486</URL>
        <Description>SUSE Bug 1187486</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkVerifyAndAssign. The highest threat from this vulnerability is to data confidentiality and to the service availability.</Note>
    </Notes>
    <CVE>CVE-2020-36330</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-36330.html</URL>
        <Description>CVE-2020-36330</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185691</URL>
        <Description>SUSE Bug 1185691</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1187486</URL>
        <Description>SUSE Bug 1187486</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds read was found in function ChunkAssignData. The highest threat from this vulnerability is to data confidentiality and to the service availability.</Note>
    </Notes>
    <CVE>CVE-2020-36331</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>critical</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.4</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:P/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>9.1</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-36331.html</URL>
        <Description>CVE-2020-36331</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185686</URL>
        <Description>SUSE Bug 1185686</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1187486</URL>
        <Description>SUSE Bug 1187486</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.</Note>
    </Notes>
    <CVE>CVE-2020-36332</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:libwebp6-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebp6-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpdecoder2-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpextras0-32bit-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-0.5.0-3.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:libwebpmux2-32bit-0.5.0-3.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>5</BaseScoreV2>
        <VectorV2>AV:N/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/4ZIJ3ZK5FGNGJN6E65XZKMQPSQ3RKNVG/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-36332.html</URL>
        <Description>CVE-2020-36332</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1185674</URL>
        <Description>SUSE Bug 1185674</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1187486</URL>
        <Description>SUSE Bug 1187486</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
