home.social

#libvpx — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #libvpx, aggregated by home.social.

  1. #CyberVeille #libwebp #libvpx

    🗒️ petit résumé / annotations surs les deux vulnérabilités basés sur les denières information disponibles au 29.09

    "CVE-2023-5217 [ ndr 𝐥𝐢𝐛𝐯𝐩𝐱 ] requires a targeted device to create media in the VP8 format.

    CVE-2023-4863 [ndr 𝐖𝐞𝐛𝐏 / 𝐥𝐢𝐛𝐰𝐞𝐛𝐏 ] could be exploited when a targeted device simply displayed a booby-trapped image."
    👇
    arstechnica.com/security/2023/

    CVE-2023-5129 ➡️ Retirée par Mitre Duplicata CVE-2023-4863
    👇
    cve.org/CVERecord?id=CVE-2023-

    ------------------------

    liste utile pour (merci @mttaggart ) suivi CVE-2023-4863 dans apps Electron
    👇
    docs.google.com/spreadsheets/d

    FAQ CVE-2023-4863 par Tenable
    👇
    tenable.com/blog/cve-2023-4106

    ------------------------

    Annonce CVE-2023-5217
    👇
    chromereleases.googleblog.com/

  2. New 0-day in Chrome and Firefox will likely plague other software - Enlarge (credit: Getty Images)

    A critical zero-day vulnerabili... - arstechnica.com/?p=1972043 #security #zero-day #exploit #firefox #libwebp #biz#chrome #libvpx

  3. Maybe relying on one company's browser product for your entire computer is not a good idea.

    #libWebP #libVPX #Electron

  4. *Sigh*, another one of these:

    "CVE-2023-5217: Heap buffer overflow in vp8 encoding in #libvpx."
    "Google is aware that an exploit for CVE-2023-5217 exists in the wild."

    Note that because it's in an underlying (video codec) library, it's probably going to be an issue in every browser and video player and electron app; just like the prior #libwebp #security bug.