short answer: yes
slightly longer answer:
i'll refer you back to your original link https://www.tarlogic.com/blog/cve-2023-4863/

scroll down to the table that show fixed versions.
short answer: yes
That's a good info for everyone interested which version has a fix (and of course any newer versions than the one listed has the fix as well)ncmprhnsbl wrote: ↑28 Sep 2023, 05:38i'll refer you back to your original link https://www.tarlogic.com/blog/cve-2023-4863/
scroll down to the table that show fixed versions.
Code: Select all
Affected Version Fixed Version Documentation
Google Chrome Ver. 116.0.5845.187 (Mac and Linux)
Ver. 116.0.5845.187/.188 (Windows) https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html
Mozilla Firefox Ver. 117.0.1
Ver. ESR 102.15.1
Ver. ESR 115.2.1 https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/
Thunderbird Ver. 102.15.1
Ver. 115.2.2
Microsoft Edge Ver. 116.0.1938.81 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863
Brave Ver. 1.58.124 https://github.com/brave/brave-browser/issues/33032
Opera Ver. 102.0.4880.51 https://blogs.opera.com/desktop/2023/09/opera-102-0-4880-51-stable-update/
Vivaldi Ver. 6.2 https://vivaldi.com/blog/desktop/minor-update-three-6-2/
Honeyview Ver. 5.51 https://en.bandisoft.com/honeyview/history/
Here I've got something to read:Rava wrote: ↑29 Sep 2023, 11:08Found nothing on CVE-2023-4863 via https://www.blender.org/download/releases/ (or more specifically https://www.blender.org/download/releases/3-6/ ) nor via https://wiki.blender.org/ nor via https://devtalk.blender.org/
Most browsers use an internal routine for viewing webp internally because historically SM-Witless (or it is called MS-Weirdness?) had no support for webp in its OS environment.
Not true !
WebP --->4 %Which image format is most widely used on the Internet in 2023 ? The answer is PNG, with a usage rate of 82.1%, followed closely by JPEG at 77.9%
( Source : https://security-tracker.debian.org/tra ... ge/libwebp )CVE-2023-4863 Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.1 ...
CVE-2023-1999 There exists a use after free/double free in libwebp. An attacker can ...
CVE-2020-36332 A flaw was found in libwebp in versions before 1.0.1. When reading a f ...
CVE-2020-36331 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds ...
CVE-2020-36330 A flaw was found in libwebp in versions before 1.0.1. An out-of-bounds ...
CVE-2020-36329 A flaw was found in libwebp in versions before 1.0.1. A use-after-free ...
CVE-2020-36328 A flaw was found in libwebp in versions before 1.0.1. A heap-based buf ...
CVE-2018-25014 A use of uninitialized value was found in libwebp in versions before 1 ...
CVE-2018-25013 A heap-based buffer overflow was found in libwebp in versions before 1 ...
CVE-2018-25012 A heap-based buffer overflow was found in libwebp in versions before 1 ...
CVE-2018-25011 A heap-based buffer overflow was found in libwebp in versions before 1 ...
CVE-2018-25010 A heap-based buffer overflow was found in libwebp in versions before 1 ...
CVE-2018-25009 A heap-based buffer overflow was found in libwebp in versions before 1 ...
CVE-2016-9969 In libwebp 0.5.1, there is a double free bug in libwebpmux.
CVE-2016-9085 Multiple integer overflows in libwebp allows attackers to have unspeci ...
CVE-2012-5127 Integer overflow in Google Chrome before 23.0.1271.64 allows remote at .
Code: Select all
$ ls -oSr forum.porteus.org_rem*
-rw-r--r-- 1 guest 25422 2023-09-20 09:20 forum.porteus.org_rem_lossless.webp
-rw-r--r-- 1 guest 123434 2023-09-20 09:20 forum.porteus.org_rem.webp
-rw-r--r-- 1 guest 148685 2023-09-20 09:20 forum.porteus.org_rem.png