oss-sec mailing list archives
Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec
From: Salvatore Bonaccorso <carnil () debian org>
Date: Tue, 26 Sep 2023 11:43:45 +0200
Hi, On Thu, Sep 21, 2023 at 10:52:50PM +0200, Solar Designer wrote:
Hi, Ideally this should have been brought in here ~10 days ago, but I guess better late than never, and I'd like to encourage others to be bringing relevant stuff to the list. On September 11, Google announced an update to Chrome: https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html fixing this issue:Critical CVE-2023-4863: Heap buffer overflow in WebP. Reported by Apple Security Engineering and Architecture (SEAR) and The Citizen Lab at The University of Toronto's Munk School on 2023-09-06 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel. Google is aware that an exploit for CVE-2023-4863 exists in the wild.With the bug being in a library used by many projects, this made people wonder why a CVE was assigned to Chrome rather than to libwebp: https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/
Maybe related to this question in todays CVEs updates there appeared https://www.cve.org/CVERecord?id=CVE-2023-5129 vs. https://www.cve.org/CVERecord?id=CVE-2023-4863 FWIW, I contacted the assigning CNAs so this can be clarified (e.g. if one of those needs to be rejected). Regards, Salvatore
Current thread:
- CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Solar Designer (Sep 21)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Hanno Böck (Sep 21)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Solar Designer (Sep 22)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Vincent Rabaud (Sep 22)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Solar Designer (Sep 22)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Vincent Rabaud (Sep 22)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Solar Designer (Sep 22)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Hanno Böck (Sep 21)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Marc Deslauriers (Sep 22)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Rodrigo Freire (Sep 22)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Solar Designer (Sep 26)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Salvatore Bonaccorso (Sep 28)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Jeffrey Walton (Sep 28)
- Re: CVE-2023-4863: libwebp: Heap buffer overflow in WebP Codec Emilio Pozuelo Monfort (Sep 28)
