This isn't the first time CVE abuse for libraries has happened.
Take the recent libweb vulnerability. Apple got the report and assigned CVE-2023-41064 to "ImageIO"
Google got the report and assigned CVE-2023-4863 to "Chrome"
Eventually MITRE fixed the latter CVE to be libwebp.
Embed Notice
HTML Code
Corresponding Notice
- Embed this notice
Will Dormann (wdormann@infosec.exchange)'s status on Wednesday, 17-Jan-2024 03:57:08 JSTWill Dormann