Opened 8 months ago

Closed 8 months ago

#18543 closed enhancement (fixed)

firefox-115.2.1 (Critical Security Update for shipped libwebp)

Reported by: Douglas R. Reno Owned by: ken@…
Priority: normal Milestone: 12.1
Component: BOOK Version: git
Severity: trivial Keywords:
Cc:

Description

New point version.

Contains a security fix for a security vulnerability which is currently under active exploitation.

It appears to be in libwebp. However, Google has locked the bug report to anyone outside of a distribution's security team, and thus we have no context as to where the commit is that fixes this vulnerability in libwebp.

From the Mozilla security advisory:

CVE-2023-4863: Heap buffer overflow in libwebp

Reporter
    Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Toronto's Munk School
Impact
    critical

Description

Opening a malicious WebP image could lead to a heap buffer overflow in 
the content process. We are aware of this issue being exploited in other 
products in the wild.

References

    Bug https://bugzilla.mozilla.org/show_bug.cgi?id=1852649
    Bug https://bugs.chromium.org/p/chromium/issues/detail?id=1479274

Change History (3)

comment:1 by ken@…, 8 months ago

Owner: changed from blfs-book to ken@…
Status: newassigned

Given webp's past tardiness in releasing new versions (the previous vulnerability was specified in firefox's media/libwebp/CHANGES file for a long time before the webp-1.3.1 release), I propose to patch webp with the fix extracted from firefox (assuming it builds) plus an indication in the .pc file that it has been patched.

For 115.2.0 only this item has changed, for 117.0.1 there are other fixes. For anyone using firefox-beta, 118.0b8 has now been released and includes this (but does not point to the webp commit in the libwebp/MOZCHANGES file.

comment:2 by ken@…, 8 months ago

Priority: highnormal
Summary: firefox-115.2.1 (Critical Security Update)firefox-115.2.1 (Critical Security Update for shipped libwebp)

I've committed the system libwebp fix, so since we don't use the shipped webp this is not a security update for people who follow the book.

comment:3 by ken@…, 8 months ago

Resolution: fixed
Status: assignedclosed
Note: See TracTickets for help on using tickets.