Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[flutter_releases] Flutter stable 3.13.4 Engine Cherrypicks #45742

Conversation

@flutter-dashboard
Copy link

This pull request was opened from and to a release candidate branch. This should only be done as part of the official Flutter release process. If you are attempting to make a regular contribution to the Flutter project, please close this PR and follow the instructions at Tree Hygiene for detailed instructions on contributing to Flutter.

Reviewers: Use caution before merging pull requests to release branches. Ensure the proper procedure has been followed.

Copy link
Contributor

@Jasguerrero Jasguerrero left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Contributor

@XilaiZhang XilaiZhang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

images (1)

@itsjustkevin itsjustkevin merged commit 9064459 into flutter:flutter-3.13-candidate.0 Sep 13, 2023
23 checks passed
@ua741
Copy link

ua741 commented Sep 28, 2023

Hello @itsjustkevin `,

As per flutter 3.13.4 change log, that this commit Fixes CVE-2023-4863.

According to libwebp repo, the fix for CVE-2023-4863 was released as part of v1.3.2 . The libwebp v1.3.1 doesn't contain the fix for CVE-2023-4863

cc @licaon-kter who noticed this issue first.

@linsui
Copy link

linsui commented Sep 28, 2023

In fec13df the libwebp is updated to 1.3.1 2af26267cdfcb63a88e5c74a85927a12d6ca1d76. The webmproject/libwebp@2af2626 commit is the fix of the 0day backported to the 1.3.1 branch.

@ua741
Copy link

ua741 commented Sep 29, 2023

In fec13df the libwebp is updated to 1.3.1 2af26267cdfcb63a88e5c74a85927a12d6ca1d76. The webmproject/libwebp@2af2626 commit is the fix of the 0day backported to the 1.3.1 branch.

Thank you for clarifying.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

6 participants