VDB
Sign up
HIGH

GHSA-4c29-gfrp-g6x9

CefSharp affected by libvpx's heap buffer overflow in vp8 encoding

Quick fix

GHSA-4c29-gfrp-g6x9 — CefSharp.Common: upgrade to the fixed version with the command below.

dotnet add package CefSharp.Common --version 117.2.20

Details

Google is aware that an exploit for CVE-2023-5217 exists in the wild.

Description Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

References - https://www.cve.org/CVERecord?id=CVE-2023-5217 - https://nvd.nist.gov/vuln/detail/CVE-2023-5217

Are you affected?

Enter the version of the package you're using.

Affected packages

NuGet/CefSharp.Common
Introduced in: 0Fixed in: 117.2.20
Fixdotnet add package CefSharp.Common --version 117.2.20
NuGet/CefSharp.Common.NETCore
Introduced in: 0Fixed in: 117.2.20
Fixdotnet add package CefSharp.Common.NETCore --version 117.2.20

References