this post was submitted on 28 Sep 2023
124 points (99.2% liked)
Firefox
17811 readers
12 users here now
A place to discuss the news and latest developments on the open-source browser Firefox
founded 4 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Fix is to address a critical CVE:
Any idea if it's the same root cause as CVE-2023-4863 (libwebp heap buffer overflow)? WEBP is a derivative of VP8, after all.
It is apparently a new one in libvpx