﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
17918	libwebp double-free	ken@…	ken@…	"In firefox-112.0 and 102.10.0 mozilla cherry-picked a fix for libwebp. The release notes say this could lead to memory corruption and a potentially exploitable crash, so mozilla rate the severity as High.

Reference MFSA-TMP-2023-0001, no release from libwebp at the moment (webp bug 603). [https://www.mozilla.org/en-US/security/advisories/mfsa2023-14/]

Unlike the mozilla binaries, BLFS uses system libwebp. I have a patch.
"	enhancement	closed	elevated	12.0	BOOK	git	medium	fixed		
