]> git.ipfire.org Git - thirdparty/openembedded/openembedded-core.git/commit
libwebp: Fix CVE-2023-4863
authorSoumya Sambu <soumya.sambu@windriver.com>
Fri, 3 Nov 2023 08:54:54 +0000 (08:54 +0000)
committerSteve Sakoman <steve@sakoman.com>
Wed, 8 Nov 2023 02:31:19 +0000 (16:31 -1000)
commite2bd9494b59b486000320c6814371f37828d4c2d
treedf9c6309c98e947e5c0fe8c264047d1656f1b900
parent3625bed6d7432091bfb144314b8ef979b5246e4c
libwebp: Fix CVE-2023-4863

Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187
allowed a remote attacker to perform an out of bounds memory write via
a crafted HTML page.

Removed CVE-2023-5129.patch as CVE-2023-5129 is duplicate of CVE-2023-4863.

CVE: CVE-2023-4863

References:
https://nvd.nist.gov/vuln/detail/CVE-2023-4863
https://security-tracker.debian.org/tracker/CVE-2023-4863
https://bugzilla.redhat.com/show_bug.cgi?id=2238431#c12

Signed-off-by: Soumya Sambu <soumya.sambu@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
meta/recipes-multimedia/webp/files/CVE-2023-4863-0001.patch [moved from meta/recipes-multimedia/webp/files/CVE-2023-5129.patch with 97% similarity]
meta/recipes-multimedia/webp/files/CVE-2023-4863-0002.patch [new file with mode: 0644]
meta/recipes-multimedia/webp/libwebp_1.3.1.bb