this post was submitted on 28 Sep 2023
124 points (99.2% liked)

Firefox

17811 readers
12 users here now

A place to discuss the news and latest developments on the open-source browser Firefox

founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 15 points 1 year ago (1 children)

Fix is to address a critical CVE:

Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.

[–] [email protected] 2 points 1 year ago (1 children)

Any idea if it's the same root cause as CVE-2023-4863 (libwebp heap buffer overflow)? WEBP is a derivative of VP8, after all.

[–] [email protected] 4 points 1 year ago

It is apparently a new one in libvpx