Double-free in stbi__load_gif_main_outofmem in stb_image
CVE-2023-45664
7.3HIGH
What is CVE-2023-45664?
The stb_image library, a widely used MIT licensed image processing tool, faces a vulnerability stemming from its GIF loading functionality. When a specific crafted GIF file is processed, the 'stbi__load_gif_main_outofmem' function can attempt a double-free of memory due to faulty handling of the 'layers * stride' value. This scenario, mainly occurring in a multi-threaded context, could facilitate exploitation, potentially leading to unauthorized code execution and further system ramifications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
stb <= 2.28
