Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2023-1999
Description:There exists a use after free/double free in libwebp. An attacker can use the ApplyFiltersAndEncode() function and loop through to free best.bw and assign best = trial pointer. The second loop will then return 0 because of an Out of memory error in VP8 encoder, the pointer is still assigned to trial and the AddressSanitizer will attempt a double free.
Test IDs: 1.3.6.1.4.1.25623.1.1.2.2023.2695   1.3.6.1.4.1.25623.1.1.12.2023.6078.2   1.3.6.1.4.1.25623.1.1.12.2023.6078.1   1.3.6.1.4.1.25623.1.1.2.2023.2618   1.3.6.1.4.1.25623.1.1.2.2023.2961   1.3.6.1.4.1.25623.1.0.884294   1.3.6.1.4.1.25623.1.1.1.1.2023.5408   1.3.6.1.4.1.25623.1.1.2.2023.2562   1.3.6.1.4.1.25623.1.1.2.2023.2730   1.3.6.1.4.1.25623.1.1.4.2023.2552.1   1.3.6.1.4.1.25623.1.1.2.2023.2761   1.3.6.1.4.1.25623.1.1.2.2023.3402   1.3.6.1.4.1.25623.1.1.2.2023.2588   1.3.6.1.4.1.25623.1.1.2.2023.2653   1.3.6.1.4.1.25623.1.1.2.2023.2385   1.3.6.1.4.1.25623.1.1.2.2023.2987   1.3.6.1.4.1.25623.1.1.2.2023.2359   1.3.6.1.4.1.25623.1.1.1.2.2023.3439   1.3.6.1.4.1.25623.1.1.2.2023.2543  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2023-1999
https://security.gentoo.org/glsa/202309-05
https://chromium.googlesource.com/webm/libwebp
https://chromium.googlesource.com/webm/libwebp




© 1998-2025 E-Soft Inc. All rights reserved.