A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0699.json",
"cwe_ids": [
"CWE-416"
],
"cna_assigner": "fedora"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.5.0"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:osgeo:shapelib:*:*:*:*:*:*:*:*"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-0699.json"
"2026-07-22T02:22:53Z"
[
{
"digest": {
"function_hash": "83108686154979985158517561713373035900",
"length": 748.0
},
"id": "CVE-2022-0699-836bb0c7",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/osgeo/shapelib/commit/c75b9281a5b9452d92e1682bdfe6019a13ed819f",
"signature_type": "Function",
"target": {
"function": "split",
"file": "contrib/shpsort.c"
}
}
]