From 46f68a6c6b2dafba09253bde40393a72d25c62f3 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 13 May 2025 20:52:32 +0000 Subject: [PATCH] Publish GHSA-j7hp-h8jx-5ppr --- .../GHSA-j7hp-h8jx-5ppr/GHSA-j7hp-h8jx-5ppr.json | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2023/09/GHSA-j7hp-h8jx-5ppr/GHSA-j7hp-h8jx-5ppr.json b/advisories/github-reviewed/2023/09/GHSA-j7hp-h8jx-5ppr/GHSA-j7hp-h8jx-5ppr.json index 677b707a75a..a6c9383c806 100644 --- a/advisories/github-reviewed/2023/09/GHSA-j7hp-h8jx-5ppr/GHSA-j7hp-h8jx-5ppr.json +++ b/advisories/github-reviewed/2023/09/GHSA-j7hp-h8jx-5ppr/GHSA-j7hp-h8jx-5ppr.json @@ -1,13 +1,13 @@ { "schema_version": "1.4.0", "id": "GHSA-j7hp-h8jx-5ppr", - "modified": "2024-02-12T15:56:30Z", + "modified": "2025-05-13T20:50:31Z", "published": "2023-09-12T15:30:20Z", "aliases": [ "CVE-2023-4863" ], "summary": "libwebp: OOB write in BuildHuffmanTable", - "details": "Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page. ", + "details": "Heap buffer overflow in libwebp allow a remote attacker to perform an out of bounds memory write via a crafted HTML page.", "severity": [ { "type": "CVSS_V3", @@ -178,6 +178,9 @@ "events": [ { "introduced": "1.0.0" + }, + { + "fixed": "1.4.0" } ] } @@ -419,7 +422,7 @@ }, { "type": "WEB", - "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I" + "url": "https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway" }, { "type": "WEB", @@ -459,7 +462,7 @@ }, { "type": "WEB", - "url": "https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway" + "url": "https://www.vicarius.io/vsociety/posts/zero-day-webp-vulnerability-cve-2023-4863" }, { "type": "WEB", @@ -533,6 +536,10 @@ "type": "WEB", "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHOLML7N2G5KCAZXFWC5IDFFHSQS5SDB" }, + { + "type": "WEB", + "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WTRUIS3564P7ZLM2S2IH4Y4KZ327LI4I" + }, { "type": "WEB", "url": "http://www.openwall.com/lists/oss-security/2023/09/21/4"