Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-4vjr-crvh-383h: @napi-rs/image affected by libwebp CVE

Impact

Heap buffer overflow in libwebp allows a remote attacker to perform an out of bounds memory write via a crafted webp image.

References

  • https://github.com/advisories/GHSA-j7hp-h8jx-5ppr
  • https://blog.isosceles.com/the-webp-0day/
ghsa
#web#git#buffer_overflow

@napi-rs/image affected by libwebp CVE

High severity GitHub Reviewed Published Sep 27, 2023 in Brooooooklyn/Image • Updated Sep 27, 2023

ghsa: Latest News

GHSA-qg5g-gv98-5ffh: rustls network-reachable panic in `Acceptor::accept`