CVE-2023-45664
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Oct 21, 2023
Updated: Nov 4, 2023
CWE ID 415
Summary
CVE-2023-45664 is a vulnerability affecting the stb_image library, which is used for processing images. A maliciously crafted image file can cause the library to attempt to double-free memory in the function `stbi__load_gif_main_outofmem`. This occurs when the `layers * stride` value is zero, leading to implementation-defined behavior. In some cases, this may result in the library freeing old memory before allocating new memory, creating an opportunity for potential code execution in a multi-threaded environment.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share