{"id":"GHSA-94vc-p8w7-5p49","aliases":[],"url":"https://o3.security/vulnerability/GHSA-94vc-p8w7-5p49","summary":"Bundled libwebp in imagecodecs vulnerable","details":"imagecodecs versions before v2023.9.18 bundled libwebp binaries in wheels that are vulnerable to CVE-2023-5129 (previously CVE-2023-4863). imagecodecs v2023.9.18 upgrades the bundled libwebp binary to v1.3.2.","published":"2023-10-05T00:07:46Z","modified":"2024-11-28T05:41:59.007222Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"imagecodecs","fixedVersion":"2023.9.18"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4863"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-5129"},{"type":"PACKAGE","url":"https://github.com/cgohlke/imagecodecs"},{"type":"WEB","url":"https://github.com/cgohlke/imagecodecs/blob/v2023.9.18/CHANGES.rst"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/imagecodecs/PYSEC-2023-174.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-11-28T05:41:59.007222Z"}}