Exploitation Summary
EIP tracks 1 public exploit for CVE-2023-6350. PoCs published by dywsy21.
AI-analyzed exploit summary This repository contains a fuzzing driver for CVE-2023-6350, targeting the GD library's AVIF image parsing functionality. The fuzzer uses libFuzzer to test for crashes or memory corruption in `gdImageCreateFromAvif`.
Description
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
Exploits (1)
This repository contains a fuzzing driver for CVE-2023-6350, targeting the GD library's AVIF image parsing functionality. The fuzzer uses libFuzzer to test for crashes or memory corruption in `gdImageCreateFromAvif`.
References (7)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H