[GLSA-202309-05] WebP: Multiple vulnerabilities

Severity Normal
Affected Packages 1
Unaffected Packages 1
CVEs 2

Multiple vulnerabilities have been discovered in WebP, the worst of which could result in remote code execution.

Background
WebP is an image format employing both lossy and lossless compression.

Description
Multiple vulnerabilities have been discovered in WebP. Please review the CVE identifiers referenced below for details.

Impact
Please review the CVE identifiers referenced below for details.

Workaround
There is no known workaround at this time.

Resolution
All WebP users should upgrade to the latest version:

# emerge --sync
# emerge --ask --oneshot --verbose ">=media-libs/libwebp-1.3.1_p20230908"

Package Affected Version
pkg:ebuild/media-libs/libwebp?distro=gentoo < 1.3.1_p20230908
Package Unaffected Version
pkg:ebuild/media-libs/libwebp?distro=gentoo >= 1.3.1_p20230908
ID
GLSA-202309-05
Severity
normal
URL
https://security.gentoo.org/glsa/202309-05
Published
2023-09-17T00:00:00
(12 months ago)
Modified
2023-09-17T00:00:00
(12 months ago)
Rights
Gentoo Foundation, Inc.
Other Advisories
Source # ID Name URL
CVE CVE-2023-1999 CVE-2023-1999 https://nvd.nist.gov/vuln/detail/CVE-2023-1999
CVE CVE-2023-4863 CVE-2023-4863 https://nvd.nist.gov/vuln/detail/CVE-2023-4863
Bugzilla 909369 Bugzilla #909369 https://bugs.gentoo.org/show_bug.cgi?id=909369
Bugzilla 914010 Bugzilla #914010 https://bugs.gentoo.org/show_bug.cgi?id=914010
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:ebuild/media-libs/libwebp?distro=gentoo media-libs libwebp < 1.3.1_p20230908 gentoo
Unaffected pkg:ebuild/media-libs/libwebp?distro=gentoo media-libs libwebp >= 1.3.1_p20230908 gentoo
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...