CVE Vulnerabilities

CVE-2016-9969

Double Free

Published: May 23, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

In libwebp 0.5.1, there is a double free bug in libwebpmux.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Libwebp Webmproject 0.5.1 (including) 0.5.1 (including)
Firefox Ubuntu trusty *
Godot Ubuntu disco *
Godot Ubuntu eoan *
Godot Ubuntu groovy *
Godot Ubuntu hirsute *
Godot Ubuntu impish *
Godot Ubuntu kinetic *
Godot Ubuntu lunar *
Godot Ubuntu mantic *
Godot Ubuntu trusty *
Libwebp Ubuntu trusty *
Mozjs38 Ubuntu bionic *
Mozjs38 Ubuntu esm-apps/bionic *
Mozjs38 Ubuntu upstream *
Mozjs52 Ubuntu bionic *
Mozjs52 Ubuntu cosmic *
Mozjs52 Ubuntu disco *
Mozjs52 Ubuntu eoan *
Mozjs52 Ubuntu esm-apps/focal *
Mozjs52 Ubuntu esm-infra/bionic *
Mozjs52 Ubuntu focal *
Mozjs52 Ubuntu groovy *
Mozjs52 Ubuntu upstream *
Mozjs60 Ubuntu cosmic *
Mozjs60 Ubuntu disco *
Mozjs60 Ubuntu eoan *
Mozjs60 Ubuntu upstream *
Qtimageformats-opensource-src Ubuntu bionic *
Qtimageformats-opensource-src Ubuntu cosmic *
Qtimageformats-opensource-src Ubuntu disco *
Qtimageformats-opensource-src Ubuntu eoan *
Qtimageformats-opensource-src Ubuntu groovy *
Qtimageformats-opensource-src Ubuntu hirsute *
Qtimageformats-opensource-src Ubuntu impish *
Qtimageformats-opensource-src Ubuntu kinetic *
Qtimageformats-opensource-src Ubuntu lunar *
Qtimageformats-opensource-src Ubuntu mantic *
Qtimageformats-opensource-src Ubuntu trusty *
Qtimageformats-opensource-src Ubuntu xenial *
Qtwebengine-opensource-src Ubuntu bionic *
Qtwebengine-opensource-src Ubuntu cosmic *
Qtwebengine-opensource-src Ubuntu disco *
Qtwebengine-opensource-src Ubuntu eoan *
Qtwebengine-opensource-src Ubuntu groovy *
Qtwebengine-opensource-src Ubuntu hirsute *
Qtwebengine-opensource-src Ubuntu impish *
Qtwebengine-opensource-src Ubuntu kinetic *
Qtwebengine-opensource-src Ubuntu lunar *
Qtwebengine-opensource-src Ubuntu mantic *
Qtwebengine-opensource-src Ubuntu trusty *

Potential Mitigations

References