VDB
KO
HIGH 8.8

GHSA-qqvq-6xgj-jw8g

Electron affected by libvpx's heap buffer overflow in vp8 encoding

Details

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / electron
Introduced in: 0 Fixed in: 22.3.25
Fix npm install electron@22.3.25
npm / electron
Introduced in: 24.0.0 Fixed in: 24.8.5
Fix npm install electron@24.8.5
npm / electron
Introduced in: 25.0.0 Fixed in: 25.8.4
Fix npm install electron@25.8.4
npm / electron
Introduced in: 26.0.0 Fixed in: 26.2.4
Fix npm install electron@26.2.4
npm / electron
Introduced in: 27.0.0-alpha.1 Fixed in: 27.0.0-beta.8
Fix npm install electron@27.0.0-beta.8

References