this post was submitted on 28 Sep 2023
125 points (99.2% liked)

Firefox

20531 readers
66 users here now

/c/firefox

A place to discuss the news and latest developments on the open-source browser Firefox.


Rules

1. Adhere to the instance rules

2. Be kind to one another

3. Communicate in a civil manner


Reporting

If you would like to bring an issue to the moderators attention, please use the "Create Report" feature on the offending comment or post and it will be reviewed as time allows.


founded 5 years ago
MODERATORS
top 3 comments
sorted by: hot top controversial new old
[–] TwinHaelix@reddthat.com 15 points 2 years ago (1 children)

Fix is to address a critical CVE:

Specific handling of an attacker-controlled VP8 media stream could lead to a heap buffer overflow in the content process. We are aware of this issue being exploited in other products in the wild.

[–] pivot_root@lemmy.world 2 points 2 years ago (1 children)

Any idea if it's the same root cause as CVE-2023-4863 (libwebp heap buffer overflow)? WEBP is a derivative of VP8, after all.

[–] Audacity9961@feddit.ch 4 points 2 years ago

It is apparently a new one in libvpx