Google assigns a CVE for libwebp and gives it a 10.0 score

In case you missed the news, there’s a critical 0day in WebP (a heap buffer overflow in the libwepb library) floating about, which was initially issued as CVE-2023-4863 and assigned specifically to Google Chrome. At the time this happened, I wrote my blog post about it and vehemently tried to make it clear that it wasn’t just Chrome that was affected, but any software that uses libwebp to render WebP images.

That story exploded. 🤯

unreachable,
@unreachable@lemmy.world avatar

any working “demo” in the wild?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • cybersecurity@lemmy.capebreton.social
  • DreamBathrooms
  • khanakhh
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • rosin
  • ethstaker
  • modclub
  • Youngstown
  • slotface
  • osvaldo12
  • kavyap
  • ngwrru68w68
  • everett
  • JUstTest
  • GTA5RPClips
  • tacticalgear
  • Durango
  • normalnudes
  • mdbf
  • provamag3
  • cisconetworking
  • cubers
  • tester
  • Leos
  • megavids
  • anitta
  • lostlight
  • All magazines