A double-free condition exists in contrib/shpsort.c of shapelib 1.5.0 and older releases. This issue may allow an attacker to cause a denial of service or have other unspecified impact via control over malloc.
{ "vanir_signatures": [ { "id": "CVE-2022-0699-836bb0c7", "signature_type": "Function", "target": { "file": "contrib/shpsort.c", "function": "split" }, "digest": { "function_hash": "83108686154979985158517561713373035900", "length": 748.0 }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/osgeo/shapelib/commit/c75b9281a5b9452d92e1682bdfe6019a13ed819f" } ] }