CVE-2023-45664

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Oct 21, 2023
Updated: Nov 4, 2023
CWE ID 415

Summary

CVE-2023-45664 is a vulnerability affecting the stb_image library, which is used for processing images. A maliciously crafted image file can cause the library to attempt to double-free memory in the function `stbi__load_gif_main_outofmem`. This occurs when the `layers * stride` value is zero, leading to implementation-defined behavior. In some cases, this may result in the library freeing old memory before allocating new memory, creating an opportunity for potential code execution in a multi-threaded environment.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share