Re: Is Guacamole susceptible to the WEBP Exploit | CVE-2023-4863

2023-09-27 Thread Michael Jumper
On 9/27/2023 8:50 AM, Caleb Coverdale wrote: Hey there, I was wondering if ApacheGuacamole was susceptible to the webp exploit that was announced. I see in the Guacamole Server code that it is using WebP as the encoder, so I assume that it may be? https://github.com/apache/guacamole-server/bl

Is Guacamole susceptible to the WEBP Exploit | CVE-2023-4863

2023-09-27 Thread Caleb Coverdale
Hey there, I was wondering if ApacheGuacamole was susceptible to the webp exploit that was announced. I see in the Guacamole Server code that it is using WebP as the encoder, so I assume that it may be? https://github.com/apache/guacamole-server/blob/master/src/libguac/encode-webp.c Just won