Hal-5700X to [email protected] • 1 year agoFirefox 118.1 releasedwww.mozilla.orgexternal-linkmessage-square3arrow-up1128arrow-down11file-textcross-posted to: [email protected]firefox
arrow-up1127arrow-down1external-linkFirefox 118.1 releasedwww.mozilla.orgHal-5700X to [email protected] • 1 year agomessage-square3file-textcross-posted to: [email protected]firefox
minus-square@[email protected]linkfedilink14•1 year agoFix is to address a critical CVE: Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.
minus-square@pivot_rootlink2•1 year agoAny idea if it’s the same root cause as CVE-2023-4863 (libwebp heap buffer overflow)? WEBP is a derivative of VP8, after all.
Fix is to address a critical CVE:
Any idea if it’s the same root cause as CVE-2023-4863 (libwebp heap buffer overflow)? WEBP is a derivative of VP8, after all.
It is apparently a new one in libvpx