mmomtchev / node-gdal-async

Node.js bindings for GDAL (Geospatial Data Abstraction Library) with full async support
https://mmomtchev.github.io/node-gdal-async/
Apache License 2.0
129 stars 26 forks source link

libwebp vulnerability #106

Closed jdesboeufs closed 11 months ago

jdesboeufs commented 11 months ago

Hello,

Considering this are we sure WebP features are not available in the default gdal-async bundle? It's just to get a confirmation :)

Thank you in advance.

mmomtchev commented 11 months ago

WebP support is not included in the bundled binary.

However people using their own system-installed (or custom-built) version of GDAL (ie those who installed with npm i gdal-async --build-from-source --shared_gdal) built against a vulnerable libwebp will be vulnerable until they upgrade their libraries and rebuild their GDAL.

mmomtchev commented 11 months ago

In case you haven't already read my profile, I am currently living in total isolation since I am being extorted by the French police and the French judiciary about a series of falsified criminal proceedings including false rape charges and sexual harassment. They are trying to cover up those affairs because they are linked to the personal problem of the man who is behind that affair and the fact that these have been organized with corruption of judicial officials. The French police came a week ago, without any official order and drew their guns in an attempt to further intimidate me.

In order to show me that I have to shut up about that affair, people are simultaneously posting issues on my projects. Yours is one of these. You don't happen to know anything?