Opened 3 years ago

Closed 3 years ago

#18649 closed enhancement (overcomebyevents)

firefox-115.3.1 (wait for next version)

Reported by: Bruce Dubbs Owned by: blfs_book
Priority: normal Milestone: 99-Waiting
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

No good deed goes unpunished.

Change History (7)

comment:1 by Xi Ruoyao, 3 years ago

CVE-2023-5217: Heap buffer overflow in libvpx

Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.

I'm not sure if it affects system libvpx configuration.

comment:2 by Xi Ruoyao, 3 years ago

Yes, it's a libvpx vulnerability. See #18651.

comment:3 by pierre, 3 years ago

Owner: changed from blfs-book to pierre
Status: newassigned

comment:4 by ken@…, 3 years ago

The only change, apart fro mthe version number, is in shipped libvpx

comment:5 by Xi Ruoyao, 3 years ago

So if we use the system libvpx like the book recommends, there is no reason to upgrade...

comment:6 by pierre, 3 years ago

Milestone: 12.199-Waiting
Owner: changed from pierre to blfs_book
Status: assignednew
Summary: firefox-115.3.1firefox-115.3.1 (wait for next version)

Ok, will give back the ticket

comment:7 by ken@…, 3 years ago

Resolution: overcomebyevents
Status: newclosed
Note: See TracTickets for help on using tickets.