Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2023.3092 libwebp security update 1 June 2023 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: libwebp Publisher: Debian Operating System: Debian GNU/Linux Resolution: Patch/Upgrade CVE Names: CVE-2023-1999 Original Bulletin: https://lists.debian.org/debian-lts-announce/2023/05/msg00031.html Comment: CVSS (Max): 7.5 CVE-2023-1999 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) CVSS Source: Red Hat Calculator: https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H - --------------------------BEGIN INCLUDED TEXT-------------------- - -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3439-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb May 31, 2023 https://wiki.debian.org/LTS - - ------------------------------------------------------------------------- Package : libwebp Version : 0.6.1-2+deb10u2 CVE ID : CVE-2023-1999 Debian Bug : 1035371 It was discovered that there was a potential arbitrary code execution vulnerability in libwebp, a library to support the WebP image compression format. For Debian 10 buster, this problem has been fixed in version 0.6.1-2+deb10u2. We recommend that you upgrade your libwebp packages. For the detailed security status of libwebp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libwebp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmR3USUACgkQHpU+J9Qx Hlgk5A//a3Qlw0G4vn1+oDWJTSlDIbDvLDo9kxgQ7QDUpU8ZZUlB4M15Tqd32WFh x045+uaZF58aQpSbhggAUp30Aluf7aX6TSyTy7BaJOrG47VfBEVr8Xt9Vn8KGJRf ra3TXfjHemDnyA/fMFIlYlt3mbp4CaWhiHvax0E/7uDIotrEmdjCRa8k0c9nECcP MR1GcI18G/o9Vyuv2mXFvB26iH6QZ5ar84YpVunEaUNdaPv/JGPFVPAew3eeOHLZ mUX3dfBG1X9DBZmgg5Fd5CIiWUfwWgh7LHN0aEVVwPj5BH7mn7Aaj6oH3kA5HflG KS3XWNbRaG2KL8Cm8h29sL9WrRJfcZPg5tz5IWLjh4gedP2TdufnqK0BmvWWUphI DbE5GjmgXgR89oq6hnzuDEkbL3rDt9Ax4bQXdf31I3KZIq2Amxu1dGAa621NUguX BhBx8TdzdgoofIDd3cqKe22iBbnBuVDERoMbOElqdPZOwzr7MgIf7/a/qc9oIYRC JXVd0gvM1oCSaSvTzunsnENpKGV7sRE8v448tJHYI7AuVv1LMVdBVJQmyk/yAXqV QLdSvuYknOhv2K/5Jvtogbkzc8F0BB+icDyrmPCVdyoh862f59YvN0MqgYD4XBSC 1cuDjdkejbF+u1gtkhGAjgs4/jnBqsBtnwMUhytKaj9HFKVYJBw= =MwwM - -----END PGP SIGNATURE----- - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: https://auscert.org.au/gpg-key/ iQIVAwUBZHfwK8kNZI30y1K9AQgj7w//fcCpHhLa+iqv5rPMAqEoQj3vHHqW1hET cL/EI0H3rstCjVqKcQI9qLZJdbVga847n0BO2BSRH7Al3/z6rx/ylqriUsvCs+/y 7pAsGjycNBcKWU803QDzNgnbEu51JNz5NRWNZekQwOQ3y9/f0cdw4LN2qNDokgz3 NbQIIuF74L91qxF/X63IWFF3O3Fqr3IcmIsrrSvbN/iM7zfkq4bbirfFyqfjRmvl 5e5TgAZMQ2v4qWalVgNr+qpICRwZR2me2awM0Nx67z+KZvlBbp5BD/nBYGfOfzb3 GWKNgSxgkKVH4lmLeaYOKxRqHvhZJG35vjvTdeOsl3cCF5GmWPHz+ZNYMkNmbCHb wDuTvTrtN0MITSe9t0RkzGmdgGC8QgfYqlc1sIwq47KxVNyCNvWhAmT047mpF1cx AZi0oQ1A2JRwtQBl0i98JdBpEpLScMOTvgz5tYoiiBBjLNreWvRj6HzuD7zsGVmg umJK8pqqk/oAli2e3r/oIUzYJpPCVLjkbc8AN3ExcVqLsZiIBFHFslp8IIlCXHdN Cwz7g2z9s79WnkyiR6rqEBlmZXSH8sTAvY6h+edcwUACD10lcNiTmzyx0E90z7NK AhiIv8e2xrEU3gW2gWt7LUZIgXJqR9DX59c2eGj/bKeImeomrmnjB0MOcqOwB9E7 RxkpRBrpyk8= =Tr8g -----END PGP SIGNATURE-----