Double Free in Mozilla products - CVE-2023-1999

 

Double Free in Mozilla products - CVE-2023-1999

Published: April 11, 2023 / Updated: April 28, 2023


Vulnerability identifier: #VU74824
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-1999
CWE-ID: CWE-415
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in libwebp. A remote attacker can trick the victim to visit a specially crafted page, trigger a double free error and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Mozilla Firefox
Firefox ESR
Microsoft Edge
Firefox for Android
Firefox Focus for Android
Oracle Linux
Debian Linux
Gentoo Linux
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Workstation Extension 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
CentOS
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for ARM 64
SUSE OpenStack Cloud
HPE Helion Openstack
Red Hat Enterprise Linux for x86_64
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Solaris
SUSE Linux Enterprise Server 12 SP2 BCL
SUSE Linux Enterprise Server 12 SP4 LTSS
SUSE Linux Enterprise Server 12 SP4 ESPOS
SUSE Package Hub 15
Basesystem Module
openSUSE Leap
Ubuntu
openEuler
Data Lakehouse
Red Hat Advanced Cluster Management for Kubernetes
Oracle Communications Diameter Signaling Router
Isolation Segment
VMware Tanzu Application Service for VMs
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libwebpmux1 (Ubuntu package)
libwebpdemux1 (Ubuntu package)
libwebp5 (Ubuntu package)
libwebp
libwebp-devel
libwebp-tools
libwebp-java
libwebp (Red Hat package)
libwebp5-debuginfo
libwebpmux1
libwebpmux1-debuginfo
libwebp-debugsource
libwebp5-32bit
libwebpdemux1
libwebp5-debuginfo-32bit
libwebpdemux1-debuginfo
libwebpdecoder1-debuginfo
libwebp5
libwebpdecoder1
libwebp6-debuginfo
libwebp6-32bit
libwebpdecoder2-32bit
libwebpdecoder2-32bit-debuginfo
libwebpdecoder2
libwebpdecoder2-debuginfo
libwebpextras0-debuginfo
libwebp6
libwebpmux2
libwebp6-32bit-debuginfo
libwebpmux2-32bit
libwebpextras0
libwebpmux2-debuginfo
libwebpextras0-32bit-debuginfo
libwebpmux2-32bit-debuginfo
libwebpextras0-32bit
libwebp6 (Ubuntu package)
libwebpmux3 (Ubuntu package)
libwebpdemux2 (Ubuntu package)
libwebp (Debian package)
libwebp-devel-32bit
libwebpdecoder3-32bit
libwebpdemux2-32bit-debuginfo
libwebp7-32bit-debuginfo
libwebp7-32bit
libwebpdemux2
libwebp-tools-debuginfo
libwebpdemux2-debuginfo
libwebp7
libwebpmux3
libwebpdecoder3-debuginfo
libwebp7-debuginfo
libwebpdecoder3
libwebpmux3-debuginfo
libwebpdecoder3-32bit-debuginfo
libwebpmux3-32bit-debuginfo
libwebpmux3-32bit
libwebpdemux2-32bit
libwebp-help
libwebp-debuginfo
libwebp7 (Ubuntu package)
mail-client/thunderbird-bin
mail-client/thunderbird
MozillaThunderbird-debugsource
MozillaThunderbird-translations-other
MozillaThunderbird-debuginfo
MozillaThunderbird
MozillaThunderbird-translations-common
firefox-debugsource
firefox-debuginfo
firefox
mozjs102-debugsource
mozjs102-devel
mozjs102-debuginfo
mozjs102
www-client/firefox
Mozilla Thunderbird
cflinuxfs3
IBM Qradar SIEM

How to mitigate CVE-2023-1999

Install updates from vendor's website.

Mozilla Firefox - update to 112.0
Firefox for Android - update to 112.0
Firefox ESR - update to 102.10.0
Firefox Focus for Android - update to 112.0
Data Lakehouse - update to 1.1.0.0
Migration Toolkit for Containers - update to 1.7.10
Red Hat Advanced Cluster Management for Kubernetes - addressed in versions 2.5.9, 2.6.6
Red Hat OpenShift Container Platform - update to 4.12.16
Microsoft Edge - update to 114.0.1823.67
Mozilla Thunderbird - update to 102.10.0
libwebpmux1 (Ubuntu package) - update to Ubuntu Pro
libwebpdemux1 (Ubuntu package) - update to Ubuntu Pro
libwebp5 (Ubuntu package) - update to Ubuntu Pro
libwebp - addressed in versions 0.3.0-11, 1.2.0-5.0.1, 1.2.0-6.0.1
libwebp-devel - addressed in versions 0.3.0-11, 1.2.0-5.0.1, 1.2.0-6.0.1
libwebp-tools - update to 0.3.0-11
libwebp-java - update to 0.3.0-11
libwebp (Red Hat package) - addressed in versions 0.3.0-11.el7, 1.0.0-5.2.el8_1, 1.0.0-7.el8_2, 1.0.0-7.el8_4, 1.0.0-7.el8_6, 1.0.0-8.el8_7, 1.2.0-5.el9_0, 1.2.0-6.el9_1
libwebp5-debuginfo - update to 0.4.3-4.10.1
libwebpmux1 - update to 0.4.3-4.10.1
libwebpmux1-debuginfo - update to 0.4.3-4.10.1
libwebp-debugsource - addressed in versions 0.4.3-4.10.1, 0.5.0-150000.3.11.1, 1.0.3-150200.3.5.1
libwebp5-32bit - update to 0.4.3-4.10.1
libwebpdemux1 - update to 0.4.3-4.10.1
libwebp5-debuginfo-32bit - update to 0.4.3-4.10.1
libwebpdemux1-debuginfo - update to 0.4.3-4.10.1
libwebp-devel - addressed in versions 0.4.3-4.10.1, 1.0.3-150200.3.5.1
libwebpdecoder1-debuginfo - update to 0.4.3-4.10.1
libwebp5 - update to 0.4.3-4.10.1
libwebpdecoder1 - update to 0.4.3-4.10.1
libwebp6-debuginfo - update to 0.5.0-150000.3.11.1
libwebp6-32bit - update to 0.5.0-150000.3.11.1
libwebpdecoder2-32bit - update to 0.5.0-150000.3.11.1
libwebpdecoder2-32bit-debuginfo - update to 0.5.0-150000.3.11.1
libwebpdecoder2 - update to 0.5.0-150000.3.11.1
libwebpdecoder2-debuginfo - update to 0.5.0-150000.3.11.1
libwebpextras0-debuginfo - update to 0.5.0-150000.3.11.1
libwebp6 - update to 0.5.0-150000.3.11.1
libwebpmux2 - update to 0.5.0-150000.3.11.1
libwebp6-32bit-debuginfo - update to 0.5.0-150000.3.11.1
libwebpmux2-32bit - update to 0.5.0-150000.3.11.1
libwebpextras0 - update to 0.5.0-150000.3.11.1
libwebpmux2-debuginfo - update to 0.5.0-150000.3.11.1
libwebpextras0-32bit-debuginfo - update to 0.5.0-150000.3.11.1
libwebpmux2-32bit-debuginfo - update to 0.5.0-150000.3.11.1
libwebpextras0-32bit - update to 0.5.0-150000.3.11.1
libwebp6 (Ubuntu package) - addressed in versions 0.6.1-2ubuntu0.18.04.2, 0.6.1-2ubuntu0.20.04.2
libwebpmux3 (Ubuntu package) - addressed in versions 0.6.1-2ubuntu0.18.04.2, 0.6.1-2ubuntu0.20.04.2, 1.2.2-2ubuntu0.22.04.1, 1.2.2-2ubuntu0.22.10.1, 1.2.4-0.1ubuntu0.23.04.1
libwebpdemux2 (Ubuntu package) - addressed in versions 0.6.1-2ubuntu0.18.04.2, 0.6.1-2ubuntu0.20.04.2, 1.2.2-2ubuntu0.22.04.1, 1.2.2-2ubuntu0.22.10.1, 1.2.4-0.1ubuntu0.23.04.1
libwebp (Debian package) - update to 0.6.1-2.1+deb11u1
cflinuxfs3 - update to 0.365.0
libwebp-devel-32bit - update to 1.0.3-150200.3.5.1
libwebpdecoder3-32bit - update to 1.0.3-150200.3.5.1
libwebpdemux2-32bit-debuginfo - update to 1.0.3-150200.3.5.1
libwebp7-32bit-debuginfo - update to 1.0.3-150200.3.5.1
libwebp7-32bit - update to 1.0.3-150200.3.5.1
libwebpdemux2 - update to 1.0.3-150200.3.5.1
libwebp-tools-debuginfo - update to 1.0.3-150200.3.5.1
libwebpdemux2-debuginfo - update to 1.0.3-150200.3.5.1
libwebp7 - update to 1.0.3-150200.3.5.1
libwebp-tools - update to 1.0.3-150200.3.5.1
libwebpmux3 - update to 1.0.3-150200.3.5.1
libwebpdecoder3-debuginfo - update to 1.0.3-150200.3.5.1
libwebp7-debuginfo - update to 1.0.3-150200.3.5.1
libwebpdecoder3 - update to 1.0.3-150200.3.5.1
libwebpmux3-debuginfo - update to 1.0.3-150200.3.5.1
libwebpdecoder3-32bit-debuginfo - update to 1.0.3-150200.3.5.1
libwebpmux3-32bit-debuginfo - update to 1.0.3-150200.3.5.1
libwebpmux3-32bit - update to 1.0.3-150200.3.5.1
libwebpdemux2-32bit - update to 1.0.3-150200.3.5.1
libwebp - update to 1.1.0-3
libwebp-help - update to 1.1.0-3
libwebp-devel - update to 1.1.0-3
libwebp-debuginfo - update to 1.1.0-3
libwebp-tools - update to 1.1.0-3
libwebp-java - update to 1.1.0-3
libwebp-debugsource - update to 1.1.0-3
libwebp7 (Ubuntu package) - addressed in versions 1.2.2-2ubuntu0.22.04.1, 1.2.2-2ubuntu0.22.10.1, 1.2.4-0.1ubuntu0.23.04.1
libwebp - update to 1.2.4-1
Isolation Segment - addressed in versions 2.11.33, 2.13.18, 3.0.11, 4.0.2
VMware Tanzu Application Service for VMs - addressed in versions 2.11.39, 2.13.21, 3.0.11, 4.0.2
IBM Qradar SIEM - update to 7.5.0 Update Pack 6
mail-client/thunderbird-bin - update to 102.10.0
mail-client/thunderbird - update to 102.10.0
MozillaThunderbird-debugsource - update to 102.10.1-150200.8.113.2
MozillaThunderbird-translations-other - update to 102.10.1-150200.8.113.2
MozillaThunderbird-debuginfo - update to 102.10.1-150200.8.113.2
MozillaThunderbird - update to 102.10.1-150200.8.113.2
MozillaThunderbird-translations-common - update to 102.10.1-150200.8.113.2
firefox-debugsource - update to 102.14.0-1
firefox-debuginfo - update to 102.14.0-1
firefox - update to 102.14.0-1
mozjs102-debugsource - update to 102.15.1-1
mozjs102-devel - update to 102.15.1-1
mozjs102-debuginfo - update to 102.15.1-1
mozjs102 - update to 102.15.1-1
www-client/firefox - update to 104

External References

Related Security Bulletins