Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] SkiaSharp vendors libwebp vulnerable to CVE-2023-4863 #2608

Closed
1 task done
delroth opened this issue Sep 14, 2023 · 5 comments · Fixed by #2622
Closed
1 task done

[BUG] SkiaSharp vendors libwebp vulnerable to CVE-2023-4863 #2608

delroth opened this issue Sep 14, 2023 · 5 comments · Fixed by #2622
Labels

Comments

@delroth
Copy link

delroth commented Sep 14, 2023

Description

SkiaSharp vendors (via mono/skia) a version of libwebp that is vulnerable to CVE-2023-4863.

Upstream skia picked up the fixed libwebp via google/skia@1176deb

Please:

  1. Update mono's skia fork.
  2. Release a new SkiaSharp version which isn't vulnerable to CVE-2023-4863 anymore.
  3. Update the GHSA for CVE-2023-4863 (GHSA-j7hp-h8jx-5ppr) so that dependents get alerted of the vulnerability in SkiaSharp. (Happy to take care of that myself otherwise when a new release is available)

Thank you!

Code

n/a

Expected Behavior

No response

Actual Behavior

No response

Version of SkiaSharp

2.88.3 (Current)

Last Known Good Version of SkiaSharp

Other (Please indicate in the description)

IDE / Editor

Other (Please indicate in the description)

Platform / Operating System

All

Platform / Operating System Version

No response

Devices

No response

Relevant Screenshots

No response

Relevant Log Output

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct
@mattleibow
Copy link
Contributor

Thanks for the issue, PRs building and will get a release ASAP.

@darakian
Copy link

darakian commented Sep 19, 2023

@mattleibow feel free to ping over on github/advisory-database#2727 (or @ me or whatever) when ready and I can get your package (with affected versions) added to the GHSA and get dependabot alerts going out to your users if you like 😄

@mattleibow
Copy link
Contributor

Patched versions are:

@delroth
Copy link
Author

delroth commented Sep 21, 2023

Thank you very much for your help with this issue!

@JohnHSE
Copy link

JohnHSE commented Oct 5, 2023

My understanding is that webp 1.3.2 still has the vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2023-4863
@mattleibow you might want to reopen this?

EDIT: Never mind, missed the 'prior to'. Please ignore

@mono mono locked as resolved and limited conversation to collaborators Nov 4, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants