CVE-2020-36328,CVE-2020-36329.CCVE-2020-36331, VE-2020-36332 vulnerabilities
search cancel

CVE-2020-36328,CVE-2020-36329.CCVE-2020-36331, VE-2020-36332 vulnerabilities

book

Article ID: 234316

calendar_today

Updated On:

Products

Messaging Gateway for Service Providers

Issue/Introduction

Is SMG-SP 10.6 affected by CVE-2020-36328,CVE-2020-36329.CCVE-2020-36331, VE-2020-36332 vulnerabilities?

CVE-2020-36328:
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-36329:
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-36331:
A flaw was found in libwebp in versions before 1.0.1. A heap-based buffer overflow in function WebPDecodeRGBInto is possible due to an invalid check for buffer size. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-36332:
A flaw was found in libwebp in versions before 1.0.1. When reading a file libwebp allocates an excessive amount of memory. The highest threat from this vulnerability is to the service availability.

Resolution

Messaging Gateway for Service Providers (SMG-SP)10.6 is not affected by these vulnerabilities