HIGH
GHSA-4c29-gfrp-g6x9
CefSharp affected by libvpx's heap buffer overflow in vp8 encoding
Quick fix
GHSA-4c29-gfrp-g6x9 — CefSharp.Common: upgrade to the fixed version with the command below.
dotnet add package CefSharp.Common --version 117.2.20Details
Google is aware that an exploit for CVE-2023-5217 exists in the wild.
Description Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
References - https://www.cve.org/CVERecord?id=CVE-2023-5217 - https://nvd.nist.gov/vuln/detail/CVE-2023-5217
Are you affected?
Enter the version of the package you're using.
Affected packages
NuGet/CefSharp.Common
Introduced in:
0Fixed in: 117.2.20Fix
dotnet add package CefSharp.Common --version 117.2.20NuGet/CefSharp.Common.NETCore
Introduced in:
0Fixed in: 117.2.20Fix
dotnet add package CefSharp.Common.NETCore --version 117.2.20