Re: [OE-core][kirkstone][PATCH 1/1] libwebp: Fix CVE-2023-4863

2023-10-31 Thread Soumya via lists.openembedded.org
Yes Anuj, I will correct it and will send v2. Regards, Soumya From: Mittal, Anuj Sent: Tuesday, October 31, 2023 10:25 AM To: openembedded-core@lists.openembedded.org ; Sambu, Soumya Subject: Re: [OE-core][kirkstone][PATCH 1/1] libwebp: Fix CVE-2023-4863

Re: [OE-core][kirkstone][PATCH 1/1] libwebp: Fix CVE-2023-4863

2023-10-30 Thread Anuj Mittal
On Tue, 2023-10-31 at 04:37 +, Soumya via lists.openembedded.org wrote: > From: Soumya Sambu > > Heap buffer overflow in WebP in Google Chrome prior to > 116.0.5845.187 allowed a remote attacker to perform an > out of bounds memory write via a crafted HTML page. > > References: > https://nvd

Patchtest results for [OE-core][kirkstone][PATCH 1/1] libwebp: Fix CVE-2023-4863

2023-10-30 Thread Soumya via lists.openembedded.org
Thank you for your submission. Patchtest identified one or more issues with the patch. Please see the log below for more information: --- Testing patch /home/patchtest/share/mboxes/kirkstone-1-1-libwebp-Fix-CVE-2023-4863.patch FAIL: test CVE presence in commit message: A CVE tag should be provid

[OE-core][kirkstone][PATCH 1/1] libwebp: Fix CVE-2023-4863

2023-10-30 Thread Soumya via lists.openembedded.org
From: Soumya Sambu Heap buffer overflow in WebP in Google Chrome prior to 116.0.5845.187 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. References: https://nvd.nist.gov/vuln/detail/CVE-2023-4863 https://security-tracker.debian.org/tracker/CVE-2023-486