facebook / facebook/fresco

Fresco uses libjpeg-turbo 1.5.3 to have CVE-2020-17541 and CVE-2018-14498 vulnerabilities. Is there a repair plan?

Open
#2,619 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
Kotlin
Stars
17.2k
Forks
3.7k
PR merge metrics
No merged PRs in 30d

Description

### Description

libjpeg-turbo 1.5.3 has CVE-2020-17541 and CVE-2018-14498 vulnerabilities. I tested the version of libjpeg-turbo 2.1.0 and the vulnerability has been resolved. Can fresco be able to upgrade the version of libjpeg?

### Solution

https://github.com/libjpeg-turbo/libjpeg-turbo

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.