CVE Vulnerabilities

CVE-2023-43281

Double Free

Published: Oct 25, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbi_load_gif_main function.

Weakness

The product calls free() twice on the same memory address.

Affected Software

NameVendorStart VersionEnd Version
Stb_image.hNothings2.28 (including)2.28 (including)
Arm-compute-libraryUbuntubionic*
Arm-compute-libraryUbuntulunar*
Arm-compute-libraryUbuntumantic*
Arm-compute-libraryUbuntuoracular*
Arm-compute-libraryUbuntuplucky*
Arm-compute-libraryUbuntutrusty*
Arm-compute-libraryUbuntuxenial*
ArmnnUbuntubionic*
ArmnnUbuntulunar*
ArmnnUbuntumantic*
ArmnnUbuntuoracular*
ArmnnUbuntutrusty*
ArmnnUbuntuxenial*
BibleditUbuntubionic*
BibleditUbuntufocal*
BibleditUbuntulunar*
BibleditUbuntumantic*
BibleditUbuntuoracular*
BibleditUbuntuplucky*
BibleditUbuntutrusty*
BibleditUbuntuxenial*
Bibledit-cloudUbuntubionic*
Bibledit-cloudUbuntufocal*
Bibledit-cloudUbuntulunar*
Bibledit-cloudUbuntumantic*
Bibledit-cloudUbuntuoracular*
Bibledit-cloudUbuntuplucky*
Bibledit-cloudUbuntutrusty*
Bibledit-cloudUbuntuxenial*
EmscriptenUbuntubionic*
EmscriptenUbuntulunar*
EmscriptenUbuntumantic*
EmscriptenUbuntuoracular*
EmscriptenUbuntuplucky*
EmscriptenUbuntutrusty*
EmscriptenUbuntuxenial*
GoxelUbuntubionic*
GoxelUbuntufocal*
GoxelUbuntulunar*
GoxelUbuntumantic*
GoxelUbuntuoracular*
GoxelUbuntuplucky*
GoxelUbuntutrusty*
GoxelUbuntuxenial*
LibsfmlUbuntubionic*
LibsfmlUbuntufocal*
LibsfmlUbuntulunar*
LibsfmlUbuntumantic*
LibsfmlUbuntuoracular*
LibsfmlUbuntuplucky*
LibsfmlUbuntutrusty*
LibsfmlUbuntuxenial*
LibstbUbuntubionic*
LibstbUbuntufocal*
LibstbUbuntulunar*
LibstbUbuntumantic*
LibstbUbuntuoracular*
LibstbUbuntuplucky*
LibstbUbuntutrusty*
LibstbUbuntuxenial*
LoveUbuntubionic*
LoveUbuntufocal*
LoveUbuntulunar*
LoveUbuntumantic*
LoveUbuntuoracular*
LoveUbuntuplucky*
LoveUbuntutrusty*
LoveUbuntuxenial*
MameUbuntubionic*
MameUbuntufocal*
MameUbuntulunar*
MameUbuntumantic*
MameUbuntuoracular*
MameUbuntutrusty*
MameUbuntuxenial*
TimgUbuntubionic*
TimgUbuntulunar*
TimgUbuntumantic*
TimgUbuntuoracular*
TimgUbuntuplucky*
TimgUbuntutrusty*
TimgUbuntuxenial*
Tiny-dnnUbuntubionic*
Tiny-dnnUbuntulunar*
Tiny-dnnUbuntumantic*
Tiny-dnnUbuntuoracular*
Tiny-dnnUbuntuplucky*
Tiny-dnnUbuntutrusty*
Tiny-dnnUbuntuxenial*
UtoxUbuntubionic*
UtoxUbuntufocal*
UtoxUbuntulunar*
UtoxUbuntumantic*
UtoxUbuntuoracular*
UtoxUbuntuplucky*
UtoxUbuntutrusty*
UtoxUbuntuxenial*
VispUbuntubionic*
VispUbuntulunar*
VispUbuntumantic*
VispUbuntuoracular*
VispUbuntuplucky*
VispUbuntutrusty*
VispUbuntuxenial*

Potential Mitigations

References