chai2010 / chai2010/webp

CVE-2023-4863 impacting libwebp 1.0.2

Open
#61 4 comments 8 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
723
Forks
113
PR merge metrics
No merged PRs in 30d

Description

Hi!

This Go library vendors libwebp 1.0.2, which is vulnerable to CVE-2023-4863 (critical severity buffer overflow in libwebp image decoding). Upstream has a 1.0.3 available with the vulnerability fixed: https://github.com/webmproject/libwebp/tree/1.0.3

Could you please update the vendored libwebp and tag a new release of this library so dependents can get updated?

Thank you!

Contributor guide

No contributing guide indexed for this repository

Research direction

No file or test is named. First locate the vendored libwebp 1.0.2, compare it with upstream libwebp 1.0.3, and verify the CVE fix; then inspect how this library tags releases. Done means the vendored dependency is updated and a new release is available to dependents.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.