Monday, December 11, 2023
Kiratas
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
  • Home
  • World
  • Lifestyle

    Trending Tags

    • Pandemic
  • Business
  • Entertainment
  • Sports
No Result
View All Result
Kiratas
No Result
View All Result
Home World

Countless applications affected: chaos caused by WebP gap

Eliza Houghton by Eliza Houghton
September 28, 2023
in World
0
Countless applications affected: chaos caused by WebP gap
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter

Countless applications display images in Google WebP format. A vulnerability in the graphics format therefore affects all applications that use the format. Initially, Google only attributed the vulnerability to its own web browser Chrome.

Advertisement

New gap = old gap?

However, Google has now corrected itself and submitted the new entry CVE-2023-5129 with a critical rating (CVSS score 10 out of 10) for the old security vulnerability (CVE-2023-4863 “high”).

However, this was declared invalid by Google after just six hours. The reason given is that the new entry duplicates the old entry. The old entry has now been supplemented to the effect that, in addition to Chrome, the gap also affects the entire libwebp library, which many applications use.

What an attack might look like is still unclear. In the context of web browsers, we often talk about prepared HTML websites. It sounds as if visiting a website with a WebP graphic manipulated with malicious code could initiate an attack. If an attack is successful, malicious code gets onto systems.

Affected applications

These include browsers such as Edge and Firefox, Linux distributions such as Debian and Ubuntu and applications such as LibreOffice, Slack and Signal Desktop. In addition, many applications that rely on the Electron framework are affected. A security researcher is currently compiling a list of vulnerable Electron apps on Github. Electron version 1.3.2 is said to be protected against this.

The list of vulnerable applications is long and not all security updates have been released. Users should keep an eye out for patches and install them quickly. Secure editions have already been published for Firefox, Thunderbird and Tails, among others.

On (CVE-2023-41064 “high”) on Apple systems by the controversial security company NSO Group. There are currently no further details about this.

(of the)

To home page


#Countless #applications #affected #chaos #caused #WebP #gap

Tags: affectedapplicationscausedChaoscountlessgapSecurityVulnerabilitiesWebP
Previous Post

This is how the municipal rates and taxes remain in San Sebastián, which will tax empty homes at 150%

Next Post

Italy will expel migrants who declare themselves minors if the analyzes certify their majority

Eliza Houghton

Eliza Houghton

Related Posts

New business model: AI undresses people in photos
World

New business model: AI undresses people in photos

by Eliza Houghton
December 11, 2023
Indian Justice confirms the withdrawal of Kashmir’s autonomy
World

Indian Justice confirms the withdrawal of Kashmir’s autonomy

by Eliza Houghton
December 11, 2023
Spain will face the Netherlands in the final four of the Nations League
World

Spain will face the Netherlands in the final four of the Nations League

by Eliza Houghton
December 11, 2023
PHP application server in Go: FrankenPHP reaches 1.0
World

PHP application server in Go: FrankenPHP reaches 1.0

by Eliza Houghton
December 11, 2023
Guterres opens the door to ending fossil fuels at different speeds
World

Guterres opens the door to ending fossil fuels at different speeds

by Eliza Houghton
December 11, 2023
Next Post
Italy will expel migrants who declare themselves minors if the analyzes certify their majority

Italy will expel migrants who declare themselves minors if the analyzes certify their majority

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Premium Content

Argentina tries five members of the Naval Prefecture for the shooting death of a young Mapuche in 2017

Argentina tries five members of the Naval Prefecture for the shooting death of a young Mapuche in 2017

August 15, 2023
Sonia Vaccaro, forensic psychologist: “Being a mother with a violent man is an indicator of high vulnerability for women themselves”

Sonia Vaccaro, forensic psychologist: “Being a mother with a violent man is an indicator of high vulnerability for women themselves”

November 28, 2023
Spain’s real estate assets decline by 5% in 2022 and remain at 3.5 trillion

Spain’s real estate assets decline by 5% in 2022 and remain at 3.5 trillion

October 6, 2023

Browse by Category

  • Science
  • Sports
  • World

Browse by Tags

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Europe Gaza Gaza Strip Google government Hamas health investiture iOS iPhone Israel Latin America law live Madrid Microsoft million news people Politics PSOE Russia Security Spain Sports Sánchez Ukraine United States Updates Vulnerabilities war workshop world years
Kiratas

Latest News from World, Health, Politics, Sports, Business, Education, Technology, Arts and Latin America, the Middle East, South Asia.

Categories

  • Science
  • Sports
  • World

Browse by Tag

America amnesty Apple Artificial Intelligence attack attacks China Court data due Economy Europe Gaza Gaza Strip Google government Hamas health investiture iOS iPhone Israel Latin America law live Madrid Microsoft million news people Politics PSOE Russia Security Spain Sports Sánchez Ukraine United States Updates Vulnerabilities war workshop world years

Recent Posts

  • New business model: AI undresses people in photos
  • Indian Justice confirms the withdrawal of Kashmir’s autonomy
  • Spain will face the Netherlands in the final four of the Nations League
  • About Us
  • Home
  • Privacy Policy
  • Terms and Conditions

© Aroged 2023. All Rights Reserved.

No Result
View All Result
  • Home
  • Landing Page
  • Buy JNews
  • Support Forum
  • Contact Us

© Aroged 2023. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.