CVE-2023-43281: Double Free
Published Oct 24, 2023
·Updated
Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbiloadgifmain function.
Affected Software
1 affected component
Nothings Stb Image.h=2.28
Event History
Oct 24, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-43281.
2
What is the severity of CVE-2023-43281?
The severity of CVE-2023-43281 is medium with a severity value of 6.5.
3
Which software version is affected by CVE-2023-43281?
The version 2.28 of Nothings Stb Image.h is affected by CVE-2023-43281.
4
How can a remote attacker exploit CVE-2023-43281?
A remote attacker can exploit CVE-2023-43281 by sending a crafted file to the stbi_load_gif_main function.
5
Are there any references available for CVE-2023-43281?
Yes, here are the references for CVE-2023-43281: [Reference 1](https://gist.github.com/peccc/d8761f6ac45ad55cbd194dd7e6fdfdac), [Reference 2](https://github.com/peccc/double-stb).