-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2023.3092
                          libwebp security update
                                1 June 2023

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           libwebp
Publisher:         Debian
Operating System:  Debian GNU/Linux
Resolution:        Patch/Upgrade
CVE Names:         CVE-2023-1999  

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2023/05/msg00031.html

Comment: CVSS (Max):  7.5 CVE-2023-1999 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
         CVSS Source: Red Hat
         Calculator:  https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- - -------------------------------------------------------------------------
Debian LTS Advisory DLA-3439-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/                           Chris Lamb
May 31, 2023                                  https://wiki.debian.org/LTS
- - -------------------------------------------------------------------------

Package        : libwebp
Version        : 0.6.1-2+deb10u2
CVE ID         : CVE-2023-1999
Debian Bug     : 1035371

It was discovered that there was a potential arbitrary code execution
vulnerability in libwebp, a library to support the WebP image
compression format.

For Debian 10 buster, this problem has been fixed in version
0.6.1-2+deb10u2.

We recommend that you upgrade your libwebp packages.

For the detailed security status of libwebp please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libwebp

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmR3USUACgkQHpU+J9Qx
Hlgk5A//a3Qlw0G4vn1+oDWJTSlDIbDvLDo9kxgQ7QDUpU8ZZUlB4M15Tqd32WFh
x045+uaZF58aQpSbhggAUp30Aluf7aX6TSyTy7BaJOrG47VfBEVr8Xt9Vn8KGJRf
ra3TXfjHemDnyA/fMFIlYlt3mbp4CaWhiHvax0E/7uDIotrEmdjCRa8k0c9nECcP
MR1GcI18G/o9Vyuv2mXFvB26iH6QZ5ar84YpVunEaUNdaPv/JGPFVPAew3eeOHLZ
mUX3dfBG1X9DBZmgg5Fd5CIiWUfwWgh7LHN0aEVVwPj5BH7mn7Aaj6oH3kA5HflG
KS3XWNbRaG2KL8Cm8h29sL9WrRJfcZPg5tz5IWLjh4gedP2TdufnqK0BmvWWUphI
DbE5GjmgXgR89oq6hnzuDEkbL3rDt9Ax4bQXdf31I3KZIq2Amxu1dGAa621NUguX
BhBx8TdzdgoofIDd3cqKe22iBbnBuVDERoMbOElqdPZOwzr7MgIf7/a/qc9oIYRC
JXVd0gvM1oCSaSvTzunsnENpKGV7sRE8v448tJHYI7AuVv1LMVdBVJQmyk/yAXqV
QLdSvuYknOhv2K/5Jvtogbkzc8F0BB+icDyrmPCVdyoh862f59YvN0MqgYD4XBSC
1cuDjdkejbF+u1gtkhGAjgs4/jnBqsBtnwMUhytKaj9HFKVYJBw=
=MwwM
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: https://auscert.org.au/gpg-key/

iQIVAwUBZHfwK8kNZI30y1K9AQgj7w//fcCpHhLa+iqv5rPMAqEoQj3vHHqW1hET
cL/EI0H3rstCjVqKcQI9qLZJdbVga847n0BO2BSRH7Al3/z6rx/ylqriUsvCs+/y
7pAsGjycNBcKWU803QDzNgnbEu51JNz5NRWNZekQwOQ3y9/f0cdw4LN2qNDokgz3
NbQIIuF74L91qxF/X63IWFF3O3Fqr3IcmIsrrSvbN/iM7zfkq4bbirfFyqfjRmvl
5e5TgAZMQ2v4qWalVgNr+qpICRwZR2me2awM0Nx67z+KZvlBbp5BD/nBYGfOfzb3
GWKNgSxgkKVH4lmLeaYOKxRqHvhZJG35vjvTdeOsl3cCF5GmWPHz+ZNYMkNmbCHb
wDuTvTrtN0MITSe9t0RkzGmdgGC8QgfYqlc1sIwq47KxVNyCNvWhAmT047mpF1cx
AZi0oQ1A2JRwtQBl0i98JdBpEpLScMOTvgz5tYoiiBBjLNreWvRj6HzuD7zsGVmg
umJK8pqqk/oAli2e3r/oIUzYJpPCVLjkbc8AN3ExcVqLsZiIBFHFslp8IIlCXHdN
Cwz7g2z9s79WnkyiR6rqEBlmZXSH8sTAvY6h+edcwUACD10lcNiTmzyx0E90z7NK
AhiIv8e2xrEU3gW2gWt7LUZIgXJqR9DX59c2eGj/bKeImeomrmnjB0MOcqOwB9E7
RxkpRBrpyk8=
=Tr8g
-----END PGP SIGNATURE-----