WebP: Multiple vulnerabilities — GLSA 202309-05 Multiple vulnerabilities have been discovered in WebP, the worst of which could result in remote code execution. Affected packages Package media-libs/libwebp on all architectures Affected versions < 1.3.1_p20230908 Unaffected versions >= 1.3.1_p20230908 Background WebP is an image format employing both lossy and lossless compression. Description Multiple vulnerabilities have been discovered in WebP. Please review the CVE identifiers referenced below for details. Impact Please review the CVE identifiers referenced below for details. Workaround There is no known workaround at this time. Resolution All WebP users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/libwebp-1.3.1_p20230908" References CVE-2023-1999 CVE-2023-4863