Opened 17 months ago
Closed 17 months ago
#18543 closed enhancement (fixed)
firefox-115.2.1 (Critical Security Update for shipped libwebp)
Reported by: | Douglas R. Reno | Owned by: | |
---|---|---|---|
Priority: | normal | Milestone: | 12.1 |
Component: | BOOK | Version: | git |
Severity: | trivial | Keywords: | |
Cc: |
Description
New point version.
Contains a security fix for a security vulnerability which is currently under active exploitation.
It appears to be in libwebp. However, Google has locked the bug report to anyone outside of a distribution's security team, and thus we have no context as to where the commit is that fixes this vulnerability in libwebp.
From the Mozilla security advisory:
CVE-2023-4863: Heap buffer overflow in libwebp Reporter Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Toronto's Munk School Impact critical Description Opening a malicious WebP image could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild. References Bug https://bugzilla.mozilla.org/show_bug.cgi?id=1852649 Bug https://bugs.chromium.org/p/chromium/issues/detail?id=1479274
Change History (3)
comment:1 by , 17 months ago
Owner: | changed from | to
---|---|
Status: | new → assigned |
comment:2 by , 17 months ago
Priority: | high → normal |
---|---|
Summary: | firefox-115.2.1 (Critical Security Update) → firefox-115.2.1 (Critical Security Update for shipped libwebp) |
I've committed the system libwebp fix, so since we don't use the shipped webp this is not a security update for people who follow the book.
comment:3 by , 17 months ago
Resolution: | → fixed |
---|---|
Status: | assigned → closed |
Note:
See TracTickets
for help on using tickets.
Given webp's past tardiness in releasing new versions (the previous vulnerability was specified in firefox's media/libwebp/CHANGES file for a long time before the webp-1.3.1 release), I propose to patch webp with the fix extracted from firefox (assuming it builds) plus an indication in the .pc file that it has been patched.
For 115.2.0 only this item has changed, for 117.0.1 there are other fixes. For anyone using firefox-beta, 118.0b8 has now been released and includes this (but does not point to the webp commit in the libwebp/MOZCHANGES file.