]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
libwebp: Fix CVE-2023-4863
authorSoumya Sambu <soumya.sambu@windriver.com>
Fri, 3 Nov 2023 08:55:47 +0000 (08:55 +0000)
committerSteve Sakoman <steve@sakoman.com>
Mon, 13 Nov 2023 15:34:11 +0000 (05:34 -1000)
commitb69bef1169cb33c153384be81845eaf903dc1570
tree275df8a2851b3dc37f539c1f3a2e15881bfccfc4
parent3471922461627c0f0487feb09cfdc4cfeeb3f3ca
libwebp: Fix CVE-2023-4863

Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187
allowed a remote attacker to perform an out of bounds memory write via
a crafted HTML page.

Removed CVE-2023-5129.patch as CVE-2023-5129 is duplicate of CVE-2023-4863.

CVE: CVE-2023-4863

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-4863
https://security-tracker.debian.org/tracker/CVE-2023-4863
https://bugzilla.redhat.com/show_bug.cgi?id=2238431#c12

Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-multimedia/webp/files/CVE-2023-4863-0001.patch [moved from meta/recipes-multimedia/webp/files/CVE-2023-5129.patch with 95% similarity]
meta/recipes-multimedia/webp/files/CVE-2023-4863-0002.patch [new file with mode: 0644]
meta/recipes-multimedia/webp/libwebp_1.1.0.bb