Opened 13 months ago

Closed 13 months ago

Last modified 9 months ago

#17918 closed enhancement (fixed)

libwebp double-free

Reported by: ken@… Owned by: ken@…
Priority: elevated Milestone: 12.0
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

In firefox-112.0 and 102.10.0 mozilla cherry-picked a fix for libwebp. The release notes say this could lead to memory corruption and a potentially exploitable crash, so mozilla rate the severity as High.

Reference MFSA-TMP-2023-0001, no release from libwebp at the moment (webp bug 603). https://www.mozilla.org/en-US/security/advisories/mfsa2023-14/

Unlike the mozilla binaries, BLFS uses system libwebp. I have a patch.

Change History (4)

comment:1 by ken@…, 13 months ago

Owner: changed from ken:linuxfromscratch.org to ken@…
Status: assignednew

typo when assigning

comment:2 by ken@…, 13 months ago

Book pushed in b2dcbff6a01aaa19073985b8a3908d7693db8a48 11.3-313 (maybe 11.3-312)

Note to self: read the prompts *carefully* when using 'git pull --no-ff' with more than one local commit.

Last edited 13 months ago by ken@… (previous) (diff)

comment:3 by ken@…, 13 months ago

Resolution: fixed
Status: newclosed

Security Advisory SA 11.3-015

comment:4 by Bruce Dubbs, 9 months ago

Milestone: 11.412.0

Milestone renamed

Note: See TracTickets for help on using tickets.