Description: Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) Broken commit info: Bugfix commit info: https://github.com/electron/electron/pull/40026 https://github.com/electron/electron/pull/40025 https://github.com/electron/electron/pull/40022 https://github.com/electron/electron/pull/40023 https://github.com/webmproject/libvpx/commit/3fbd1dca6a4d2dad332a2110d646e4ffef36d590 https://github.com/webmproject/libvpx/commit/af6dedd715f4307669366944cca6e0417b290282 https://github.com/electron/electron/pull/40024 https://hg.mozilla.org/mozilla-central/rev/c53f5ef77b62b79af86951a7f9130e1896b695d2
PR: https://e.gitee.com/openanolis/repos/src-anolis-os/libvpx/pulls/6