Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical WebP 0-day security CVE-2023-4863 #1011

Open
huaguoshi opened this issue Oct 6, 2023 · 3 comments
Open

Critical WebP 0-day security CVE-2023-4863 #1011

huaguoshi opened this issue Oct 6, 2023 · 3 comments
Labels

Comments

@huaguoshi
Copy link

Detailed paths
Introduced through: Podfile@0.0.0 › RNFastImage@8.6.3 › SDWebImageWebPCoder@0.8.5 › libwebp@1.2.4
Security information
Factors contributing to the scoring:
Snyk: CVSS 10.0 - CRITICAL Severity
NVD: 8.8 HIGH

libwebp is a Library to encode and decode images in WebP format.

@huaguoshi huaguoshi added the bug label Oct 6, 2023
@markosrx
Copy link

markosrx commented Oct 9, 2023

+1

@Thenlie
Copy link

Thenlie commented Oct 26, 2023

I have added the following code to my Podfile which seems to update this dependency for FastImage. Seems like an acceptable workaround for the time being.

# Dependency chain: RNFastImage -> SDWebImageWebPCoder -> libwebp
pod 'libwebp', '1.3.2', :source => 'https://cdn.cocoapods.org/'

@Thenlie
Copy link

Thenlie commented Oct 26, 2023

Also, this is a duplicate of #994

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants