Metrics
Affected Vendors & Products
No advisories yet.
Solution
Update the library to its latest stable release, if not possible backport the fix commit 2b715249f39291c86443b969a1088d59b6a89b78
Workaround
No workaround given by the vendor.
Mon, 20 Oct 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 20 Oct 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during compilation and the HTML display stack is used, to write past a heap allocated buffer possibly causing a crash, when the user visits an attacker controlled website that contains a crafted PNG file with a big width value that causes an integer overflow which value is used for determining the size of a heap allocation. | |
Title | Out-of-bounds Write in libwebsockets PNG parsing | |
Weaknesses | CWE-787 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Nozomi
Published:
Updated: 2025-10-20T14:34:57.848Z
Reserved: 2025-10-13T09:57:01.900Z
Link: CVE-2025-11680

Updated: 2025-10-20T14:34:50.372Z

Status : Received
Published: 2025-10-20T14:15:40.520
Modified: 2025-10-20T14:15:40.520
Link: CVE-2025-11680

No data.

No data.