First published: Tue Apr 11 2023(Updated: )
<p>This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see <a href="https://chromereleases.googleblog.com/2023">Google Chrome Releases</a> for more information.</p>
Credit: cve-coordination@google.com cve-coordination@google.com cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mozilla Firefox ESR | <102.10 | 102.10 |
Microsoft Edge | <114.0.1823.67 | |
Mozilla Thunderbird | <102.10 | 102.10 |
Mozilla Firefox | <112 | 112 |
All of | ||
Mozilla Firefox | =112 | |
Google Android | ||
All of | ||
Mozilla Focus | =112 | |
Google Android | ||
Microsoft Edge (Chromium-based) | ||
Webmproject Libwebp | >=0.4.2<1.3.1 | |
ubuntu/firefox | <112.0-1 | 112.0-1 |
ubuntu/libwebp | <0.6.1-2ubuntu0.18.04.2 | 0.6.1-2ubuntu0.18.04.2 |
ubuntu/libwebp | <0.6.1-2ubuntu0.20.04.2 | 0.6.1-2ubuntu0.20.04.2 |
ubuntu/libwebp | <1.2.2-2ubuntu0.22.04.1 | 1.2.2-2ubuntu0.22.04.1 |
ubuntu/libwebp | <1.2.2-2ubuntu0.22.10.1 | 1.2.2-2ubuntu0.22.10.1 |
ubuntu/libwebp | <1.2.4-0.1ubuntu0.23.04.1 | 1.2.4-0.1ubuntu0.23.04.1 |
ubuntu/libwebp | <1.2.4-0.1ubuntu1 | 1.2.4-0.1ubuntu1 |
ubuntu/libwebp | <1.2.4-0.1ubuntu1 | 1.2.4-0.1ubuntu1 |
ubuntu/libwebp | <0.4.4-1ubuntu0.1~ | 0.4.4-1ubuntu0.1~ |
debian/firefox | 127.0.2-1 | |
debian/firefox-esr | 115.12.0esr-1~deb11u1 115.12.0esr-1~deb12u1 115.12.0esr-1 | |
debian/libwebp | 0.6.1-2.1+deb11u2 1.2.4-0.2+deb12u1 1.4.0-0.1 | |
debian/thunderbird | 1:115.12.0-1~deb11u1 1:115.12.0-1~deb12u1 1:115.12.0-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
(Found alongside the following vulnerabilities)
CVE-2023-1999 is a vulnerability that allows attackers to cause memory corruption and potentially exploitable crashes in libwebp due to a double-free vulnerability.
Yes, CVE-2023-1999 is considered a high severity vulnerability.
The software affected by CVE-2023-1999 includes Thunderbird, Firefox, Firefox ESR, and libwebp.
To fix CVE-2023-1999, update your software to the latest version provided by the vendor.
You can find more information about CVE-2023-1999 on the official CVE page and the bug tracking systems of Mozilla and Chromium.