home.social

#libvpx — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #libvpx, aggregated by home.social.

  1. #BSI WID-SEC-2024-1945: [NEU] [mittel] #Red #Hat #Enterprise #Linux (#libvpx): Mehrere Schwachstellen ermöglichen Denial of Service

    Ein entfernter Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux in der Komponente libvpx ausnutzen, um einen Denial of Service Angriff durchzuführen.

    wid.cert-bund.de/portal/wid/se

  2. Apple releases iOS/iPad OS 17.0.3 as an emergency update to resolve an actively exploited zero day caused by a kernel vulnerability. If successful, a malicious actor can perform local privilege escalation as part of an attack chain.

    Apple also notes that they have resolved CVE-2023-5217 by updating the libvpx to 1.13.1 in iOS/iPad OS 17.0.3

    This marks the 17th zero day that Apple has addressed so far this year.

    https://www.bleepingcomputer.com/news/apple/apple-emergency-update-fixes-new-zero-day-used-to-hack-iphones/

    #infosec #cybersecurity #Apple #ios #ipados #kernel #vulnerability #CVE_2023_42824 #CVE_2023_5217 #libvpx #zeroday

  3. #CyberVeille #libwebp #libvpx

    🗒️ petit résumé / annotations surs les deux vulnérabilités basés sur les denières information disponibles au 29.09

    "CVE-2023-5217 [ ndr 𝐥𝐢𝐛𝐯𝐩𝐱 ] requires a targeted device to create media in the VP8 format.

    CVE-2023-4863 [ndr 𝐖𝐞𝐛𝐏 / 𝐥𝐢𝐛𝐰𝐞𝐛𝐏 ] could be exploited when a targeted device simply displayed a booby-trapped image."
    👇
    arstechnica.com/security/2023/

    CVE-2023-5129 ➡️ Retirée par Mitre Duplicata CVE-2023-4863
    👇
    cve.org/CVERecord?id=CVE-2023-

    ------------------------

    liste utile pour (merci @mttaggart ) suivi CVE-2023-4863 dans apps Electron
    👇
    docs.google.com/spreadsheets/d

    FAQ CVE-2023-4863 par Tenable
    👇
    tenable.com/blog/cve-2023-4106

    ------------------------

    Annonce CVE-2023-5217
    👇
    chromereleases.googleblog.com/

  4. New 0-day in Chrome and Firefox will likely plague other software - Enlarge (credit: Getty Images)

    A critical zero-day vulnerabili... - arstechnica.com/?p=1972043 #security #zero-day #exploit #firefox #libwebp #biz#chrome #libvpx

  5. Maybe relying on one company's browser product for your entire computer is not a good idea.

    #libWebP #libVPX #Electron

  6. *Sigh*, another one of these:

    "CVE-2023-5217: Heap buffer overflow in vp8 encoding in #libvpx."
    "Google is aware that an exploit for CVE-2023-5217 exists in the wild."

    Note that because it's in an underlying (video codec) library, it's probably going to be an issue in every browser and video player and electron app; just like the prior #libwebp #security bug.