CVE-2023-1999 — Use After Free in Libwebp
Severity
7.5HIGHNVD
CNA5.3
EPSS
0.4%
top 41.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 20
Latest updateSep 12
Description
There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6
Affected Packages4 packages
🔴Vulnerability Details
3💥Exploits & PoCs
1Exploit-DB▶
Microsoft IIS 1.0 / Netscape Server 1.0/1.12 / OReilly WebSite Professional 1.1b - '.cmd' / '.CMD' Remote Command Execution↗1996-03-01
📋Vendor Advisories
9Oracle▶
Oracle Oracle Communications Risk Matrix: Virtual Network Function Manager (Libwebp) — CVE-2023-1999↗2023-07-15