Skip to content

Conversation

@kornelski
Copy link
Contributor

libwebp has an exploitable heap buffer overflow. There are two Rust sys crate that have bundled the vulnerable version of libwebp. Both sys crates are patched now.

@alex
Copy link
Member

alex commented Sep 13, 2023

The TOML metadata should be in a markdown block, with a short description of each vuln, see the example advisory: https://raw.githubusercontent.com/rustsec/advisory-db/main/EXAMPLE_ADVISORY.md

@alex
Copy link
Member

alex commented Sep 13, 2023

Ooops, I forgot: the markdown always needs to have a # title

@alex alex merged commit 0636c35 into rustsec:main Sep 13, 2023
@Shnatsel
Copy link
Member

Thank you for the report!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants