Skip to content
This repository was archived by the owner on Feb 25, 2025. It is now read-only.

[flutter_releases] Flutter stable 3.13.4 Engine Cherrypicks#45742

Merged
itsjustkevin merged 2 commits into
flutter-team-archive:flutter-3.13-candidate.0from
itsjustkevin:cherrypicks-flutter-3.13-candidate.0
Sep 13, 2023
Merged

[flutter_releases] Flutter stable 3.13.4 Engine Cherrypicks#45742
itsjustkevin merged 2 commits into
flutter-team-archive:flutter-3.13-candidate.0from
itsjustkevin:cherrypicks-flutter-3.13-candidate.0

Conversation

@itsjustkevin

Copy link
Copy Markdown
Contributor

@flutter-dashboard

Copy link
Copy Markdown

This pull request was opened from and to a release candidate branch. This should only be done as part of the official Flutter release process. If you are attempting to make a regular contribution to the Flutter project, please close this PR and follow the instructions at Tree Hygiene for detailed instructions on contributing to Flutter.

Reviewers: Use caution before merging pull requests to release branches. Ensure the proper procedure has been followed.

@Jasguerrero Jasguerrero left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@XilaiZhang XilaiZhang left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

images (1)

@itsjustkevin itsjustkevin merged commit 9064459 into flutter-team-archive:flutter-3.13-candidate.0 Sep 13, 2023
@ua741

ua741 commented Sep 28, 2023

Copy link
Copy Markdown

Hello @itsjustkevin `,

As per flutter 3.13.4 change log, that this commit Fixes CVE-2023-4863.

According to libwebp repo, the fix for CVE-2023-4863 was released as part of v1.3.2 . The libwebp v1.3.1 doesn't contain the fix for CVE-2023-4863

cc @licaon-kter who noticed this issue first.

@linsui

linsui commented Sep 28, 2023

Copy link
Copy Markdown

In fec13df the libwebp is updated to 1.3.1 2af26267cdfcb63a88e5c74a85927a12d6ca1d76. The webmproject/libwebp@2af2626 commit is the fix of the 0day backported to the 1.3.1 branch.

@ua741

ua741 commented Sep 29, 2023

Copy link
Copy Markdown

In fec13df the libwebp is updated to 1.3.1 2af26267cdfcb63a88e5c74a85927a12d6ca1d76. The webmproject/libwebp@2af2626 commit is the fix of the 0day backported to the 1.3.1 branch.

Thank you for clarifying.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Development

Successfully merging this pull request may close these issues.

6 participants