Microsoft teams which most of you have installed on your machines these days as a major vulnerability. Make sure you get that updated as soon as possible!

#CVE20235217 #vulnerability #cybersecurity

So here we go again? After libwebp, libvpx is next in line with CVE-2023-5217: another exploited-in-the-wild buffer overflow in a media encoding library used in Chrome et al. ๐Ÿ˜ฉโ€‹

#infosec #CVE20235217 #cve

"๐Ÿš€ #ChromeSecurityUpdate: Google Thwarts Spyware Vendor Exploiting New Zero-Day ๐Ÿš€"

Google has promptly patched a fresh security flaw in Chrome, exploited by a commercial spyware vendor. The update, version 117.0.5938.132, rolled out for Windows, macOS, and Linux, addressing ten vulnerabilities. The most critical among them is CVE-2023-5217, a "heap buffer overflow in vp8 encoding in libvpx," reported by Clement Lecigne from Google's Threat Analysis Group. This flaw was already weaponized in real-world attacks, marking the sixth Chrome zero-day patched in 2023. ๐Ÿ›ก๏ธ๐Ÿ’ป

The exploit was leveraged by a commercial surveillance vendor, reminiscent of a recent operation delivering Predator spyware to an Egyptian opposition politician using various zero-days and MitM attacks on mobile devices. ๐Ÿ•ต๏ธ๐Ÿ“ฑ

Source: SecurityWeek

Tags: #CyberSecurity #GoogleChrome #ZeroDay #CVE20235217 #Spyware #CyberAttack #PatchTuesday #InfoSec #VulnerabilityManagement #MitM #RealWorldExploits

Google Rushes to Patch New Zero-Day Exploited by Spyware Vendor

Google has rushed to patch a new Chrome zero-day vulnerability, tracked as CVE-2023-5217 and exploited by a spyware vendor. 

SecurityWeek

Firefox 118.0.1 now appears to be live in #archlinux extra repository, addressing CVE-2023-5217: Heap buffer overflow in libvpx

#Linux #security #cve20235217 #libvpx

#Firefox on both #Flatpak and #Snap is already updated to 118.0.1 addressing CVE-2023-5217: Heap buffer overflow in libvpx

Make sure you are running 118.0.1 or update ASAP.

Tracking of traditional distro packages will continue throughout this thread as they arrive in various repositories (both Firefox and libvpx, along with Chromium builds not linked dynamically to the system lib - e.g. #linuxmint)

https://flathub.org/apps/org.mozilla.firefox

https://snapcraft.io/firefox

#Linux #security #cve20235217 #libvpx

Install Firefox on Linux | Flathub

Fast, Private & Safe Web Browser

Flathub - Apps for Linux

Mozilla released #Firefox 118.0.1 and ESR 115.3.1 to address CVE-2023-5217: Heap buffer overflow in libvpx

https://www.mozilla.org/en-US/security/advisories/mfsa2023-44/

I suppose I'll follow the Linux distro packages again for this one so I guess follow this thread or whatever ๐Ÿ˜‚

#security #cve20235217 #libvpx

Security Vulnerability fixed in Firefox 118.0.1, Firefox ESR 115.3.1, Firefox for Android 118.1.0, Firefox Focus for Android 118.1.0, and Thunderbird 115.3.1.

Mozilla