Skip to content

[BUG] SkiaSharp vendors libwebp vulnerable to CVE-2023-4863 #2608

@delroth

Description

@delroth

Description

SkiaSharp vendors (via mono/skia) a version of libwebp that is vulnerable to CVE-2023-4863.

Upstream skia picked up the fixed libwebp via google/skia@1176deb

Please:

  1. Update mono's skia fork.
  2. Release a new SkiaSharp version which isn't vulnerable to CVE-2023-4863 anymore.
  3. Update the GHSA for CVE-2023-4863 (GHSA-j7hp-h8jx-5ppr) so that dependents get alerted of the vulnerability in SkiaSharp. (Happy to take care of that myself otherwise when a new release is available)

Thank you!

Code

n/a

Expected Behavior

No response

Actual Behavior

No response

Version of SkiaSharp

2.88.3 (Current)

Last Known Good Version of SkiaSharp

Other (Please indicate in the description)

IDE / Editor

Other (Please indicate in the description)

Platform / Operating System

All

Platform / Operating System Version

No response

Devices

No response

Relevant Screenshots

No response

Relevant Log Output

No response

Code of Conduct

  • I agree to follow this project's Code of Conduct

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions