CVE-2023-1999

CVSS V2 None CVSS V3 None
Description
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free. 
Overview
  • CVE ID
  • CVE-2023-1999
  • Assigner
  • Google
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-06-20T11:28:52.547Z
  • Last Modified Date
  • 2023-06-20T11:28:52.547Z
History
Created Old Value New Value Data Type Notes
2024-06-25 08:38:20 Added to TrackCVE