15 points

Fix is to address a critical CVE:

Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.

permalink
report
reply
2 points

Any idea if it’s the same root cause as CVE-2023-4863 (libwebp heap buffer overflow)? WEBP is a derivative of VP8, after all.

permalink
report
parent
reply
4 points

It is apparently a new one in libvpx

permalink
report
parent
reply

Firefox

!firefox@lemmy.ml

Create post

A place to discuss the news and latest developments on the open-source browser Firefox

Community stats

  • 1.5K

    Monthly active users

  • 926

    Posts

  • 17K

    Comments

Community moderators