Printable Version of Topic

Click here to view this topic in its original format

HTMLHelp Forums _ Off Topic _ Critical WebP bug: many apps, not just browsers, under threat

Posted by: Christian J Sep 14 2023, 05:55 AM

https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863/

This may also affect image editing software such as Irfanview, Gimp and similar that may not have released patches yet:

https://irfanview-forum.de/forum/program/bugreports/98117-webp-security-cve-2023-4863#post98121

https://www.gimp.org/

Some such programs may not feature automatic updates, so remember to look out for future patches, and maybe avoid open third party WebP images in them until then. Some really old programs may not support WebP in the first place, though.

Posted by: Christian J Sep 14 2023, 08:56 AM

Seems my copy of MS Edge had to be updated from within the browser itself. I was expecting Windows Update to handle that, but it seems to be bugged now for other reasons. wacko.gif

Posted by: pandy Sep 14 2023, 12:02 PM

Oh well.

Posted by: Christian J Sep 16 2023, 10:20 AM

Seems IrfanView now has updated its WebP plugin, see link above.

Posted by: Christian J Nov 13 2023, 07:34 AM

Now GIMP also has a new patched version.

Powered by Invision Power Board (http://www.invisionboard.com)
© Invision Power Services (http://www.invisionpower.com)