CLSA-2023-1697016696
Dashboard / Vulnerabilities / CLSA-2023-1697016696
CLSA-2023-1697016696
Summary: Fix CVE(s): CVE-2023-4863, CVE-2023-4836
Details: * SECURITY UPDATE: Heap buffer overflow - debian/patches/CVE-2023-4863-pre.patch: prepare sources to be patched - debian/patches/CVE-2023-4863-1.patch: first, BuildHuffmanTable() is called to check if the data is valid. If it is and the table is not big enough, more memory is allocated. This will make sure that valid (but unoptimized because of unbalanced codes) streams are still decodable. - debian/patches/CVE-2023-4863-2.patch: fix memory error - debian/patches/CVE-2023-4863-3.patch: remove unused code - debian/patches/CVE-2023-4863-4.patch: fix pointer offset int overflow - CVE-2023-4836
Affected packages
Package
Name: libwebp-dev
Purl: pkg:deb/tuxcare/libwebp-dev?distro=ubuntu-18.04
Affected ranges
Type: ECOSYSTEM
Events:
