﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
18543	firefox-115.2.1 (Critical Security Update for shipped libwebp)	Douglas R. Reno	ken@…	"New point version.

Contains a security fix for a security vulnerability which is currently under active exploitation.

It appears to be in libwebp. However, Google has locked the bug report to anyone outside of a distribution's security team, and thus we have no context as to where the commit is that fixes this vulnerability in libwebp.

From the Mozilla security advisory:

{{{
CVE-2023-4863: Heap buffer overflow in libwebp

Reporter
    Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Toronto's Munk School
Impact
    critical

Description

Opening a malicious WebP image could lead to a heap buffer overflow in 
the content process. We are aware of this issue being exploited in other 
products in the wild.

References

    Bug https://bugzilla.mozilla.org/show_bug.cgi?id=1852649
    Bug https://bugs.chromium.org/p/chromium/issues/detail?id=1479274
}}}
"	enhancement	closed	normal	12.1	BOOK	git	trivial	fixed		
