[ALSA-2023:5309] Important: libwebp security update
Type:
security
Severity:
important
Release date:
2023-09-21
Description:
The libwebp packages provide a library and tools for the WebP graphics format. WebP is an image format with a lossy compression of digital photographic images. WebP consists of a codec based on the VP8 format, and a container based on the Resource Interchange File Format (RIFF). Webmasters, web developers and browser developers can use WebP to compress, archive, and distribute digital images more efficiently. Security Fix(es): * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 libwebp-devel-1.0.0-8.el8_8.1.aarch64.rpm 1009db88f52018e05d66db2f1cb94fe836ad4f71adf004ddbc0846e431149226
aarch64 libwebp-1.0.0-8.el8_8.1.aarch64.rpm c04b0771f75e2eecdfec55ab7cc6f67f252af826dcf8eea394dac08003e2a8f6
i686 libwebp-1.0.0-8.el8_8.1.i686.rpm 7f9b37d5bbb5890ca8905473b0602e083b1ff921cf6479970a73a1ac21ff255f
i686 libwebp-devel-1.0.0-8.el8_8.1.i686.rpm d422847ce9a48eafc00d13dc0ff9c1af0387ff309e13c09a941b2ac17272c8d4
ppc64le libwebp-devel-1.0.0-8.el8_8.1.ppc64le.rpm 04297bf39fed6dd681cfabdc093671531b8273ecf62366d02968c56b6562c3ed
ppc64le libwebp-1.0.0-8.el8_8.1.ppc64le.rpm af8b8a56479b42428452e849307fc5265605049ab7ec1166ac9f9487b9ebbffa
s390x libwebp-1.0.0-8.el8_8.1.s390x.rpm bc0ed1a0ff7da081ff42a3f40e4eea73bf65bbc5ae356f318409e470944da5c4
s390x libwebp-devel-1.0.0-8.el8_8.1.s390x.rpm c070e4ea96427aee1063d0e10b86916503666d8b5788a062ea21fca43e2c303e
x86_64 libwebp-1.0.0-8.el8_8.1.x86_64.rpm 930e2e64072667db4cbcd7cfb4e1f49eed00c57c5d86f6c616c212dbfb61423c
x86_64 libwebp-devel-1.0.0-8.el8_8.1.x86_64.rpm 99b50de750f77ccff0b411e2b9dcf433655c8c74f2821124a6e2f150e588a98c
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.