{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"Heap Buffer Overflow in libwebp WebP Codec","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2023-00008","status":"final","version":"11","initial_release_date":"2023-11-01T17:33:22+00:00","current_release_date":"2026-07-27T23:21:21.737799+00:00","revision_history":[{"date":"2023-11-01T17:33:22+00:00","number":"11","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2023-00008"},{"summary":"cve","url":"https://www.cve.org/CVERecord?id=CVE-2023-4863"}],"notes":[{"category":"summary","text":"On September 11th 2023, Google published an advisory describing a vulnerability in Google Chrome that could allow a remote attacker to potentially execute arbitrary code using a carefully crafted WebP image file. On September 25th, the vulnerability scope was expanded to include the libwebp library used by many applications beyond Google Chrome.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Fireware OS all versions","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7"}}]},{"category":"product_name","name":"WatchGuard Cloud","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"WatchGuard Cloud all versions","product_id":"CSAFPID-63d1d6a3-e3b7-4015-8a50-55d002464d8d"}}]},{"category":"product_name","name":"Secure Wi-Fi","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Secure Wi-Fi all versions","product_id":"CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8"}}]},{"category":"product_name","name":"Dimension","branches":[{"category":"product_version_range","name":"all versions","product":{"name":"Dimension all versions","product_id":"CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"On September 11th 2023, Google published an advisory describing a vulnerability in Google Chrome that could allow a remote attacker to potentially execute arbitrary code using a carefully crafted WebP image file. On September 25th, the vulnerability scope was expanded to include the libwebp library used by many applications beyond Google Chrome.","title":"Summary"}],"product_status":{"known_not_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7","CSAFPID-63d1d6a3-e3b7-4015-8a50-55d002464d8d","CSAFPID-6737224d-68ea-4d9e-80e7-1f38f4c398d8","CSAFPID-d36d565e-228e-4d9a-888a-9be70889d829"]},"cve":"CVE-2023-4863"}]}