Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-j7hp-h8jx-5ppr] libwebp: OOB write in BuildHuffmanTable #2848

Conversation

pshelton-skype
Copy link

Updates

  • Affected products

Comments
Magick.NET consumed the updated libwebp in version 13.3.0 per dlemstra/Magick.NET#1440, https://github.com/dlemstra/Magick.NET/milestone/67?closed=1

@github-actions github-actions bot changed the base branch from main to pshelton-skype/advisory-improvement-2848 October 13, 2023 18:09
@darakian
Copy link
Contributor

Hey, thanks for the suggestion, but I'm not seeing that nuget package
https://www.nuget.org/packages/Magick.NET
404s on me

@pshelton-skype
Copy link
Author

Looks like a case-sensitive search? https://www.nuget.org/packages?q=magick.net lists a bunch of different build outputs.

@darakian
Copy link
Contributor

I believe they're all different artifacts with different names. Can you confirm which are affected?

@pshelton-skype
Copy link
Author

@darakian - sorry about that. Should be updated now.

@darakian
Copy link
Contributor

Many thanks. One more ask if I may; can you provide some evidence on why those packages? Fix commits, changelogs, something like that would be awesome 👍

@pshelton-skype
Copy link
Author

@darakian - Magick.NET version 13.3.0 consumes ImageMagick 7.1.1-17 (2023-09-19). Per discussion comments from the author in ImageMagick/ImageMagick#6664, libwebp version 1.3.2 was consumed in ImageMagick 7.1.1-17. It's a little complicated for me to follow, too.

@darakian
Copy link
Contributor

Ya, that is a bit terse :(
I think the lower bound of zero is probably inaccurate, but taking a quick look I can't really figure out when webp was introduced, so I suppose we run with it for the time being. Thanks 👍

@advisory-database advisory-database bot merged commit 5a814a2 into pshelton-skype/advisory-improvement-2848 Oct 18, 2023
1 check passed
@advisory-database advisory-database bot deleted the pshelton-skype-GHSA-j7hp-h8jx-5ppr branch October 18, 2023 23:11
@advisory-database
Copy link
Contributor

Hi @pshelton-skype! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants