Unable to load image

Everyone on rdrama is now running a compromised device: vulnerability in webp discovered

https://stackdiary.com/critical-vulnerability-in-webp-codec-cve-2023-4863

https://www.mozilla.org/en-US/security/advisories/mfsa2023-40

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-4863

https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html

A significant vulnerability in the WebP Codec has been unearthed, prompting major browser vendors, including Google and Mozilla, to expedite the release of updates to address the issue.

⚠️ Important: Let me make it perfectly clear that this vulnerability doesn't just affect web browsers, it affects any software that uses the libwebp library. This includes Electron-based applications, for example - Signal. Electron patched the vulnerability yesterday. Also, software like Honeyview (from Bandisoft) released an update to fix the issue. CVE-2023-4863 was falsely marked as Chrome-only by Mitre and other organizations that track CVE's and 100% of media reported this issue as "Chrome only", when it's not.

The root of the issue lies within the "BuildHuffmanTable" function which was first introduced in 2014, the function is used to verify if the data is accurate. The vulnerability can occur when more memory is allocated if the table isn't sufficiently large for valid data.

Hope you updated your browser before loading rdrama today, bros.

49
Jump in the discussion.

No email address required.

God webps are the worst format in the world, bane of any photoshop worker. Done anyone know how to make brave not save every image in webp?

Jump in the discussion.

No email address required.

Just install imagemagick and make a context menu conversion to png, or if old school you can even use a batch file you dropt the image/folder on

It takes like two seconds

Jump in the discussion.

No email address required.

Open settings dumbass

Jump in the discussion.

No email address required.

ITS NOT FRICKING THERE R-SLUR

Jump in the discussion.

No email address required.

Open config.ini

Also, if the issue is downloading shit from rDrama become webp, then you're a fricking r-slur.

Jump in the discussion.

No email address required.

Webps are good though it's just no apps want to support it for some reason.

Jump in the discussion.

No email address required.

They're "good" except when you make an image format that's so complicated that instead of just displaying pixels on your screen, it tries to do 5000 other things and apparently has memory allocation vulnerabilities built in.

Jump in the discussion.

No email address required.

Link copied to clipboard
Action successful!
Error, please refresh the page and try again.