CVE-2023-4863 impacting libwebp 1.0.2
- Dominant language
- Go
- Stars
- 723
- Forks
- 113
- PR merge metrics
- No merged PRs in 30d
Description
Hi!
This Go library vendors libwebp 1.0.2, which is vulnerable to CVE-2023-4863 (critical severity buffer overflow in libwebp image decoding). Upstream has a 1.0.3 available with the vulnerability fixed: https://github.com/webmproject/libwebp/tree/1.0.3
Could you please update the vendored libwebp and tag a new release of this library so dependents can get updated?
Thank you!
Contributor guide
No contributing guide indexed for this repository
Research direction
No file or test is named. First locate the vendored libwebp 1.0.2, compare it with upstream libwebp 1.0.3, and verify the CVE fix; then inspect how this library tags releases. Done means the vendored dependency is updated and a new release is available to dependents.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- release, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100