CVE-2023-1999: Use after free in libwebp
Published Apr 11, 2023
·Updated
A double-free in libwebp could have led to memory corruption and a potentially exploitable crash.
Affected Software
23 affected componentsFixes available
ubuntu/firefox<112.0-1
112.0-1
ubuntu/libwebp<0.6.1-2ubuntu0.18.04.2
0.6.1-2ubuntu0.18.04.2
ubuntu/libwebp<0.6.1-2ubuntu0.20.04.2
0.6.1-2ubuntu0.20.04.2
ubuntu/libwebp<1.2.2-2ubuntu0.22.04.1
1.2.2-2ubuntu0.22.04.1
ubuntu/libwebp<1.2.2-2ubuntu0.22.10.1
1.2.2-2ubuntu0.22.10.1
ubuntu/libwebp<1.2.4-0.1ubuntu0.23.04.1
1.2.4-0.1ubuntu0.23.04.1
ubuntu/libwebp<1.2.4-0.1ubuntu1
1.2.4-0.1ubuntu1
ubuntu/libwebp<1.2.4-0.1ubuntu1
1.2.4-0.1ubuntu1
ubuntu/libwebp<0.4.4-1ubuntu0.1~
0.4.4-1ubuntu0.1~
debian/firefox
127.0.2-1
debian/firefox-esr
115.12.0esr-1~deb11u1115.12.0esr-1~deb12u1115.12.0esr-1
debian/libwebp
0.6.1-2.1+deb11u21.2.4-0.2+deb12u11.4.0-0.1
debian/thunderbird
1:115.12.0-1~deb11u11:115.12.0-1~deb12u11:115.12.0-1
Microsoft Edge (Chromium-based)
Microsoft Edge<114.0.1823.67
webmproject Libwebp>=0.4.2<1.3.1
Mozilla Thunderbird<102.10
102.10
Mozilla Firefox ESR<102.10
102.10
Mozilla Firefox<112
112
All of the following
Mozilla Firefox=112
Google Android
All of the following
Mozilla Focus=112
Google Android
Remediation
Event History
Apr 11, 2023
CVE Published
12:00 AM
Jun 20, 2023
CVE Published
via MITRE·11:28 AM
Data Sourced
via MITRE·11:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 12, 2024
Data Sourced
via Launchpad·12:15 AM
Description
Frequently Asked Questions
1
What is CVE-2023-1999?
CVE-2023-1999 is a vulnerability that allows attackers to cause memory corruption and potentially exploitable crashes in libwebp due to a double-free vulnerability.
2
Is CVE-2023-1999 a high severity vulnerability?
Yes, CVE-2023-1999 is considered a high severity vulnerability.
3
Which software is affected by CVE-2023-1999?
The software affected by CVE-2023-1999 includes Thunderbird, Firefox, Firefox ESR, and libwebp.
4
How can I fix CVE-2023-1999?
To fix CVE-2023-1999, update your software to the latest version provided by the vendor.
5
Where can I find more information about CVE-2023-1999?
You can find more information about CVE-2023-1999 on the official CVE page and the bug tracking systems of Mozilla and Chromium.