fresco icon indicating copy to clipboard operation
fresco copied to clipboard

libjpeg-turbo-1.5.3 的CVE-2018-14498 和CVE-2020-17541 漏洞

Open tanlimin201 opened this issue 3 years ago • 5 comments

We use GitHub Issues for bugs.

If you have a non-bug question, please ask on Stack Overflow: http://stackoverflow.com/questions/tagged/fresco

--- Please use this template, and delete everything above this line before submitting your issue ---

Description

nativeimagetranscoder 使用的libjpeg-turbo-1.5.3 的CVE-2018-14498 和CVE-2020-17541 漏洞,什么时候可以升级下

Reproduction

[FILL THIS OUT: How can we reproduce the bug? Provide URLs to relevant images if possible, or a sample project.]

Solution

[OPTIONAL: Do you know what needs to be done to address this issue? Ideally, provide a pull request which fixes this issue.]

Additional Information

  • Fresco version: [FILL THIS OUT]
  • Platform version: [FILL THIS OUT: specific to a particular Android version? Device?]

tanlimin201 avatar Jun 17 '21 07:06 tanlimin201

When Can I Upgrade the libjpeg-turbo Version? Because one of our projects scanned for two vulnerabilities in libjpeg turbo while relying on webpsupport. What we found in the new version of libjpeg-turbo libjpeg-turbo v1.5.3 CVE-2020-17541, libjpeg-turbo v1.5.3 CVE-2018-14498

Ahujintao avatar Jun 17 '21 11:06 Ahujintao

is there any plan?

hans-han-nj avatar Jun 24 '21 08:06 hans-han-nj

Can you update libjpeg-turbo v1.5.3 to the latest version to resolve these two vulnerabilities?

Aiyuan-h avatar Jul 08 '21 12:07 Aiyuan-h

Hey there, it looks like there has been no activity on this issue recently. Has the issue been fixed, or does it still require the community's attention? This issue may be closed if no further activity occurs. You may also label this issue as "bug" or "enhancement" and I will leave it open. Thank you for your contributions.

stale[bot] avatar Jan 09 '22 04:01 stale[bot]

Duplicates https://github.com/facebook/fresco/issues/2482

Mezzle avatar Jun 28 '22 12:06 Mezzle