3 ms·
This is a vulnerability in the WebP library, so this isn't only about Chrome. Which software is affected by this? - Android apps? - Cross-platform Flutter app
by gardaani 3y ago
This is a vulnerability in the WebP library, so this isn't only about Chrome. Which software is affected by this?
- Android apps?
- Cross-platform Flutter apps?
- Electron apps?
- Microsoft Edge and Brave (and all other Chromium based web browsers)?
- Signal and Telegram displaying WebP stickers?
- Which image editors are affected? Affinity tools, Gimp and Inkscape seem to use libwebp.
- LibreOffice displaying WebP images?
- server software such as WordPress (does it decode images to re-encode them?)?
Apple devices were also affected, but they already got a fix.
Anything else?
- duringmath 3y agoFirefox? Android WebView got patched so there's that.
- internetter 3y ago> Firefox? Yup. https://hg.mozilla.org/releases/mozilla-release/rev/e245ca2125a6eb1e2d08cc9e5824f15e1e67a566 https://hg.mozilla.org/releases/mozilla-release/rev/e245ca21...
- nlitened 3y agoHave only the recent Android phones been patched, or also 3—4+ year old phones as well?
- NoahKAndrews 3y agoPhones of that era and later get WebView patched through Google Play, so they'll get the update.
- ehsankia 3y agoThat was the whole purpose of Project Mainline [0], which turned many critical system components into modules that can be updated through the Play Store regardless of manufacturer and OS updates. Media codecs is one of the first things they turned into a module, specifically for this reason; it is one of the biggest source of security patches. I actually remember hearing a stat that 90%+ of security patches are limited to a very small handful of components (media codec, crypt lib, network stack). So by turning those into modules that can be updated independently of the OS, all Android devices get to benefit from it, even years after they're abandoned by their OEMs. [0] https://source.android.com/docs/core/ota/modular-system https://source.android.com/docs/core/ota/modular-system
- internetter 3y agolog4j again?
- miohtama 3y agoWebP is an image format so it is likely a buffer overflow. So C/C++ again.
- internetter 3y agoI mean log4j as in a widely used library that has a vulnerability impacting a vast amount of products
- deleted 3y ago[deleted]
- smith7018 3y agoI mean, it would most likely affect any software that uses libwebp. Taking a quick look at Arch's libwebp page: * allegro * emacs (lmao) * ffmpeg * freeimage * gd (required for gnuplot, fceux, graphviz, etc) * godot * openimageio * qt5/6-imageformats * sdl2_image * thunderbird * webkit2gtk * etc optionally: * gdal * imagemagick * python-pillow * python-piexif * etc Should note that a vuln doesn't mean an exploit, of course.
- deleted 3y ago[deleted]