home - all |technology - lemmyshitpost - memes - microblogmemes - politicalmemes - politics - comicstrips - news - world - fuck_ai - programmer_humor - asklemmy - linuxmemes - games - workreform - onehundredninetysix - nostupidquestions - science_memes - memes - whitepeopletwitter - more »
log in or sign up | preferences
retrolemmy.com site icon
DungFu@lemmy.world
  • overview
  • DungFu

    DungFu@lemmy.world
    joined 3 years ago
    sorted by: new top controversial old
    Is Boost for Lemmy vulnerable to the webp exploit? in c/boostforlemmy@lemmy.world
    [–] DungFu@lemmy.world [S] 1 point 2 years ago

    Not really, just temporarily not using apps where random people can post images that are not re-encoded. Turns out this is very few apps, but sadly every lemmy app falls under this category.

  • permalink
  • fedilink
  • source
  • parent
  • context
  • Is Boost for Lemmy vulnerable to the webp exploit? in c/boostforlemmy@lemmy.world
    [–] DungFu@lemmy.world [S] 2 points 2 years ago (16 children)

    Ah ok, I'll just stop using Boost until the October pixel update rolls out then

  • permalink
  • fedilink
  • source
  • parent
  • context
  • 69
    Is Boost for Lemmy vulnerable to the webp exploit? (lemmy.world)
    submitted 2 years ago by DungFu@lemmy.world to c/boostforlemmy@lemmy.world
    17 comments fedilink
     

    What version of libwebp does Boost use and if it is currently vulnerable, when can we expect an update to fix this issue? The affected versions of libwebp are 0.5.0 to 1.3.1.

    lemmy:0.19.20
    mlmym (mschae):26.3.4