﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
18544	libwebp CVE-2023-4863	ken@…	ken@…	"From #18543

{{{
This critical vulnerability has been reported, but is locked and only visible by distribution security teams. Reported by Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Toronto's Munk School

 Description

 Opening a malicious WebP image could lead to a heap buffer overflow in
 the content process. We are aware of this issue being exploited in other
 products in the wild.

 References

     Bug https://bugzilla.mozilla.org/show_bug.cgi?id=1852649
     Bug https://bugs.chromium.org/p/chromium/issues/detail?id=1479274
}}}

Firefox fixed this in 115.2.1, and libwebp releases have been slow (maybe 1.3.2 will be quicker, given the severity), so I propose to apply the diff from firefox and hope it does the job.

Clearly, updating to firefox-115.2.1 et.seq will only fix the browser if using the shipped libwebp, and potentially leaves other packages linked to libwebp vulnerable."	defect	closed	elevated	12.1	BOOK	git	medium	fixed		
