[RLSA-2023:2076] libwebp security update

Severity Important
Affected Packages 4
CVEs 1

An update is available for libwebp. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list

The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently.

Security Fix(es):

  • Mozilla: libwebp: Double-free in libwebp (CVE-2023-1999)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/rockylinux/libwebp?arch=x86_64&distro=rockylinux-8.7 rockylinux libwebp < 1.0.0-8.el8_7 rockylinux-8.7 x86_64
Affected pkg:rpm/rockylinux/libwebp?arch=aarch64&distro=rockylinux-8.7 rockylinux libwebp < 1.0.0-8.el8_7 rockylinux-8.7 aarch64
Affected pkg:rpm/rockylinux/libwebp-devel?arch=x86_64&distro=rockylinux-8.7 rockylinux libwebp-devel < 1.0.0-8.el8_7 rockylinux-8.7 x86_64
Affected pkg:rpm/rockylinux/libwebp-devel?arch=aarch64&distro=rockylinux-8.7 rockylinux libwebp-devel < 1.0.0-8.el8_7 rockylinux-8.7 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...