Logo
vulnerabilityCVE-2023-1999
Name
CVE-2023-1999
Source
NVD ( link)Debian ( link)
Description
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libwebp
Exploitable

Vulnerability Ratings#


5.3
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.5.0
Not Affected
buildroot
master
1.6.0
Not Affected
openwrt
master
1.6.0-r1
Not Affected
yocto
master
1.6.0
Not Affected
yocto
scarthgap
1.3.2
Not Affected