CVE Vulnerabilities

CVE-2016-9969

Double Free

Published: May 23, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In libwebp 0.5.1, there is a double free bug in libwebpmux.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
LibwebpWebmproject0.5.1 (including)0.5.1 (including)
FirefoxUbuntutrusty*
GodotUbuntudisco*
GodotUbuntueoan*
GodotUbuntufocal*
GodotUbuntugroovy*
GodotUbuntuhirsute*
GodotUbuntuimpish*
GodotUbuntukinetic*
GodotUbuntulunar*
GodotUbuntumantic*
GodotUbuntutrusty*
LibwebpUbuntutrusty*
Mozjs38Ubuntubionic*
Mozjs38Ubuntuesm-apps/bionic*
Mozjs38Ubuntuupstream*
Mozjs52Ubuntubionic*
Mozjs52Ubuntucosmic*
Mozjs52Ubuntudisco*
Mozjs52Ubuntueoan*
Mozjs52Ubuntuesm-apps/focal*
Mozjs52Ubuntuesm-infra/bionic*
Mozjs52Ubuntufocal*
Mozjs52Ubuntugroovy*
Mozjs52Ubuntuupstream*
Mozjs60Ubuntucosmic*
Mozjs60Ubuntudisco*
Mozjs60Ubuntueoan*
Mozjs60Ubuntuupstream*
Qtimageformats-opensource-srcUbuntubionic*
Qtimageformats-opensource-srcUbuntucosmic*
Qtimageformats-opensource-srcUbuntudisco*
Qtimageformats-opensource-srcUbuntueoan*
Qtimageformats-opensource-srcUbuntufocal*
Qtimageformats-opensource-srcUbuntugroovy*
Qtimageformats-opensource-srcUbuntuhirsute*
Qtimageformats-opensource-srcUbuntuimpish*
Qtimageformats-opensource-srcUbuntukinetic*
Qtimageformats-opensource-srcUbuntulunar*
Qtimageformats-opensource-srcUbuntumantic*
Qtimageformats-opensource-srcUbuntutrusty*
Qtimageformats-opensource-srcUbuntuxenial*
Qtwebengine-opensource-srcUbuntubionic*
Qtwebengine-opensource-srcUbuntucosmic*
Qtwebengine-opensource-srcUbuntudisco*
Qtwebengine-opensource-srcUbuntueoan*
Qtwebengine-opensource-srcUbuntufocal*
Qtwebengine-opensource-srcUbuntugroovy*
Qtwebengine-opensource-srcUbuntuhirsute*
Qtwebengine-opensource-srcUbuntuimpish*
Qtwebengine-opensource-srcUbuntukinetic*
Qtwebengine-opensource-srcUbuntulunar*
Qtwebengine-opensource-srcUbuntumantic*
Qtwebengine-opensource-srcUbuntutrusty*

Potential Mitigations

References