AIX Open Source

AIX Open Source

Share your experiences and connect with fellow developers to discover how to build and manage open source software for the AIX operating system

 View Only
  • 1.  CVE-2023-4863 on libwebp

    Posted Mon October 02, 2023 08:54 AM

    Hi,

    A customer informed me his Nessus scan identified CVE-2023-4863 through plugin 182136 (heap buffer overflow in libwebp where version is below 1.3.2).

    The current version offered on the Linux Toolbox site is 1.0.2 from 2019. Will there be an update for this package? 



    ------------------------------
    Zaki Jääskeläinen
    ------------------------------


  • 2.  RE: CVE-2023-4863 on libwebp

    Posted Fri October 06, 2023 08:15 AM

    Hi Zaki,

    Thanks for the reporting the issue.

    This is in our update list for this quarter.



    ------------------------------
    SANGAMESH
    ------------------------------