CVE-2016-9969Double Free in Libwebp

CWE-415Double Free4 documents4 sources
Severity
7.5HIGHNVD
EPSS
0.2%
top 57.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 23
Latest updateMay 24

Description

In libwebp 0.5.1, there is a double free bug in libwebpmux.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages3 packages

debiandebian/libwebp< libwebp 0.5.2-1 (bookworm)
Debianwebmproject/libwebp< 0.5.2-1+3

🔴Vulnerability Details

2
GHSA
GHSA-fhhw-9rjc-7m26: In libwebp 02022-05-24
OSV
CVE-2016-9969: In libwebp 02019-05-23

📋Vendor Advisories

1
Debian
CVE-2016-9969: libwebp - In libwebp 0.5.1, there is a double free bug in libwebpmux.2016
CVE-2016-9969 — Double Free in Debian Libwebp | cvebase