Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Webp encoder version is outdated and vulnerable #2147

Closed
soupslurpr opened this issue Feb 15, 2024 · 2 comments
Closed

Webp encoder version is outdated and vulnerable #2147

soupslurpr opened this issue Feb 15, 2024 · 2 comments

Comments

@soupslurpr
Copy link
Contributor

soupslurpr commented Feb 15, 2024

The webp encoder is vulnerable as it is using an outdated version of the webp crate (0.2.2, almost 2 years old!), please update it.

jaredforth/webp#30

@soupslurpr
Copy link
Contributor Author

Okay sorry, I forgot how cargo versions work and that it specifies any version 0.2.2 and above but under 0.3.0

@fintelia
Copy link
Contributor

Yeah, running cargo update should pull in a patched version of libwebp. Though for the record, AFAIK that specific vulnerability only impacts decoding while we only use libwebp for encoding

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants