- Joined
- Apr 11, 2023
Gamerfag panda brought CVE-2023-4863 ( https://nvd.nist.gov/vuln/detail/CVE-2023-4863 ) to my attention ( https://twitter.com/GamingAndPandas/status/1707987314708775181 ).
Apparently, particularly crafted WEBP images can be used to exploit anything linked to the library libwebp, which includes things like Chrome and derivatives, Firefox, Discord, et cetera. It was patched within a week by Debian (on -security repos, vanilla is still vulnerable), but I guess there's a new wave of exploits, and other platforms care less about security.
Given that this site is highly adversarial, it might behoove administration to temporarily disable WEBP images? IDK. I'm a white hat, not a black hat. I don't see anyone else talking about this, so I reckoned it might be worth mentioning.
Any black or grey hats here who care to calm my concerns? Pandafag isn't known for hysteria.
Apparently, particularly crafted WEBP images can be used to exploit anything linked to the library libwebp, which includes things like Chrome and derivatives, Firefox, Discord, et cetera. It was patched within a week by Debian (on -security repos, vanilla is still vulnerable), but I guess there's a new wave of exploits, and other platforms care less about security.
Given that this site is highly adversarial, it might behoove administration to temporarily disable WEBP images? IDK. I'm a white hat, not a black hat. I don't see anyone else talking about this, so I reckoned it might be worth mentioning.
Any black or grey hats here who care to calm my concerns? Pandafag isn't known for hysteria.