Bug#914315: libwebp-dev: New versions fix disclosed heap use-after-free

2021-10-19 Thread Anthony Fok
On Sat, Aug 7, 2021 at 3:00 PM Jeff Breidenbach wrote: > Maintainer is "less active" but still in good contact with upstream. > I was going to package the latest version several months ago, but > there was a soname bump and transitions were not allowed due to > Debian's release cycle. Happy to

Bug#914315: libwebp-dev: New versions fix disclosed heap use-after-free

2021-08-07 Thread Jeff Breidenbach
Maintainer is "less active" but still in good contact with upstream. I was going to package the latest version several months ago, but there was a soname bump and transitions were not allowed due to Debian's release cycle. Happy to work with anyone on updating webp.

Bug#914315: libwebp-dev: New versions fix disclosed heap use-after-free

2021-06-19 Thread Sebastian Ramacher
Control: severity -1 wishlist On 2021-03-16 09:27:12 +, Laurence Parry wrote: > Tags: fixed-upstream > > Using webp-dev on buster with test file bug.c from the second bug > mentioned above compiled with -lwebp, malloc reported: "free(): > corrupted unsorted chunks" within WebPIDelete(). > >

Bug#914315: libwebp-dev: New versions fix disclosed heap use-after-free

2021-03-16 Thread Laurence Parry
Tags: fixed-upstream Using webp-dev on buster with test file bug.c from the second bug mentioned above compiled with -lwebp, malloc reported: "free(): corrupted unsorted chunks" within WebPIDelete(). This suggests to me that the bug may be exploitable on systems with libwebp6 installed - of