Opened 8 months ago

Closed 7 months ago

#18649 closed enhancement (overcomebyevents)

firefox-115.3.1 (wait for next version)

Reported by: Bruce Dubbs Owned by: blfs_book
Priority: normal Milestone: 99-Waiting
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

No good deed goes unpunished.

Change History (7)

comment:1 by Xi Ruoyao, 8 months ago

CVE-2023-5217: Heap buffer overflow in libvpx

Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.

I'm not sure if it affects system libvpx configuration.

comment:2 by Xi Ruoyao, 8 months ago

Yes, it's a libvpx vulnerability. See #18651.

comment:3 by pierre, 8 months ago

Owner: changed from blfs-book to pierre
Status: newassigned

comment:4 by ken@…, 7 months ago

The only change, apart fro mthe version number, is in shipped libvpx

comment:5 by Xi Ruoyao, 7 months ago

So if we use the system libvpx like the book recommends, there is no reason to upgrade...

comment:6 by pierre, 7 months ago

Milestone: 12.199-Waiting
Owner: changed from pierre to blfs_book
Status: assignednew
Summary: firefox-115.3.1firefox-115.3.1 (wait for next version)

Ok, will give back the ticket

comment:7 by ken@…, 7 months ago

Resolution: overcomebyevents
Status: newclosed
Note: See TracTickets for help on using tickets.