Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Use compiled libwebp to mitigate CVE-2023-4863 #276

Merged
merged 1 commit into from
Sep 15, 2023
Merged

Conversation

n0vad3v
Copy link
Member

@n0vad3v n0vad3v commented Sep 15, 2023

libwebp CVE is fixed on https://chromium.googlesource.com/webm/libwebp/+/refs/tags/v1.3.2 tag 1.3.2

  • security fix for lossless decoder (chromium: #1479274, CVE-2023-4863)

While libwebp-dev package on debian-bookworm is still 1.2.4 (1.2.4-0.2+deb12u1), we need to compile libwebp to mitigate this CVE before new libwebp-dev is released.

@n0vad3v n0vad3v requested a review from BennyThink September 15, 2023 04:16
@github-actions
Copy link


ghcr.io/webp-sh/webp_server_go (debian 12.1)
============================================
Total: 0 (HIGH: 0, CRITICAL: 0)


@n0vad3v n0vad3v merged commit c54b8be into master Sep 15, 2023
@n0vad3v n0vad3v deleted the build-libwebp branch September 15, 2023 06:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants