Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
webp_Android10_r33_CVE-2023-1999 — Proof-of-concept exploit for CVE-2023-1999 targeting the WebP codec library on Android 10 (r33). Demonstrates a heap buffer overflow vulnerability in the libwebp library, enabling remote code execution via a crafted WebP image. | Kitploit
Tools/GitHubGitHub/pazhanivelmani/webp_android10_r33_cve-2023-1999
Static AnalysisVulnerability AnalysisCode AnalysisExploitationFuzzingBinary Analysis
GitHubpazhanivelmani/webp_android10_r33_cve-2023-1999

webp_Android10_r33_CVE-2023-1999

Proof-of-concept exploit for CVE-2023-1999 targeting the WebP codec library on Android 10 (r33). Demonstrates a heap buffer overflow vulnerability in the libwebp library, enabling remote code execution via a crafted WebP image.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
1131 year agoNot yet reviewed
Share

     /  \\/  \/  _ \/  _ )/  _ \
     \       /   __/  _  \   __/
      \__\__/\____/\_____/__/ ____  ___
            / _/ /    \    \ /  _ \/ _/
           /  \_/   / /   \ \   __/  \__
           \____/____/\_____/_____/____/v1.0.2

Description:

WebP codec: library to encode and decode images in WebP format. This package contains the library that can be used in other programs to add WebP support, as well as the command line tools 'cwebp' and 'dwebp'.

See http://developers.google.com/speed/webp

The latest source tree is available at https://chromium.googlesource.com/webm/libwebp

It is released under the same license as the WebM project. See http://www.webmproject.org/license/software/ or the "COPYING" file for details. An additional intellectual property rights grant can be found in the file PATENTS.

Building:

Windows build:

By running:

nmake /f Makefile.vc CFG=release-static RTLIBCFG=static OBJDIR=output

the directory output\release-static(x64|x86)\bin will contain the tools cwebp.exe and dwebp.exe. The directory output\release-static(x64|x86)\lib will contain the libwebp static library. The target architecture (x86/x64) is detected by Makefile.vc from the Visual Studio compiler (cl.exe) available in the system path.

Unix build using makefile.unix:

On platforms with GNU tools installed (gcc and make), running

make -f makefile.unix

will build the binaries examples/cwebp and examples/dwebp, along with the static library src/libwebp.a. No system-wide installation is supplied, as this is a simple alternative to the full installation system based on the autoconf tools (see below). Please refer to makefile.unix for additional details and customizations.

Using autoconf tools:

Prerequisites: A compiler (e.g., gcc), make, autoconf, automake, libtool. On a Debian-like system the following should install everything you need for a minimal build: $ sudo apt-get install gcc make autoconf automake libtool

When building from git sources, you will need to run autogen.sh to generate the configure script.

./configure make make install

should be all you need to have the following files

/usr/local/include/webp/decode.h /usr/local/include/webp/encode.h /usr/local/include/webp/types.h /usr/local/lib/libwebp.* /usr/local/bin/cwebp /usr/local/bin/dwebp

installed.

Note: A decode-only library, libwebpdecoder, is available using the '--enable-libwebpdecoder' flag. The encode library is built separately and can be installed independently using a minor modification in the corresponding Makefile.am configure files (see comments there). See './configure --help' for more options.

Building for MIPS Linux:

MIPS Linux toolchain stable available releases can be found at: https://community.imgtec.com/developers/mips/tools/codescape-mips-sdk/available-releases/

Add toolchain to PATH

export PATH=$PATH:/path/to/toolchain/bin

32-bit build for mips32r5 (p5600)

HOST=mips-mti-linux-gnu MIPS_CFLAGS="-O3 -mips32r5 -mabi=32 -mtune=p5600 -mmsa -mfp64
-msched-weight -mload-store-pairs -fPIE" MIPS_LDFLAGS="-mips32r5 -mabi=32 -mmsa -mfp64 -pie"

64-bit build for mips64r6 (i6400)

HOST=mips-img-linux-gnu MIPS_CFLAGS="-O3 -mips64r6 -mabi=64 -mtune=i6400 -mmsa -mfp64
-msched-weight -mload-store-pairs -fPIE" MIPS_LDFLAGS="-mips64r6 -mabi=64 -mmsa -mfp64 -pie"

./configure --host=${HOST} --build=config.guess
CC="${HOST}-gcc -EL"
CFLAGS="$MIPS_CFLAGS"
LDFLAGS="$MIPS_LDFLAGS" make make install

CMake:

With CMake, you can compile libwebp, cwebp, dwebp, gif2web, img2webp, webpinfo and the JS bindings.

Prerequisites: A compiler (e.g., gcc with autotools) and CMake. On a Debian-like system the following should install everything you need for a minimal build: $ sudo apt-get install build-essential cmake

When building from git sources, you will need to run cmake to generate the makefiles.

mkdir build && cd build && cmake ../ make make install

If you also want any of the executables, you will need to enable them through CMake, e.g.:

cmake -DWEBP_BUILD_CWEBP=ON -DWEBP_BUILD_DWEBP=ON ../

or through your favorite interface (like ccmake or cmake-qt-gui).

Use option -DWEBP_UNICODE=ON for Unicode support on Windows (with chcp 65001).

Finally, once installed, you can also use WebP in your CMake project by doing:

find_package(WebP)

which will define the CMake variables WebP_INCLUDE_DIRS and WebP_LIBRARIES.

Gradle:

The support for Gradle is minimal: it only helps you compile libwebp, cwebp and dwebp and webpmux_example.

Prerequisites: A compiler (e.g., gcc with autotools) and gradle. On a Debian-like system the following should install everything you need for a minimal build: $ sudo apt-get install build-essential gradle

When building from git sources, you will need to run the Gradle wrapper with the appropriate target, e.g. :

./gradlew buildAllExecutables

SWIG bindings:

To generate language bindings from swig/libwebp.swig at least swig-1.3 (http://www.swig.org) is required.

Currently the following functions are mapped: Decode: WebPGetDecoderVersion WebPGetInfo WebPDecodeRGBA WebPDecodeARGB WebPDecodeBGRA WebPDecodeBGR WebPDecodeRGB

Encode: WebPGetEncoderVersion WebPEncodeRGBA WebPEncodeBGRA WebPEncodeRGB WebPEncodeBGR WebPEncodeLosslessRGBA WebPEncodeLosslessBGRA WebPEncodeLosslessRGB WebPEncodeLosslessBGR

See swig/README for more detailed build instructions.

Java bindings:

To build the swig-generated JNI wrapper code at least JDK-1.5 (or equivalent) is necessary for enum support. The output is intended to be a shared object / DLL that can be loaded via System.loadLibrary("webp_jni").

Python bindings:

To build the swig-generated Python extension code at least Python 2.6 is required. Python < 2.6 may build with some minor changes to libwebp.swig or the generated code, but is untested.

Encoding tool:

The examples/ directory contains tools for encoding (cwebp) and decoding (dwebp) images.

The easiest use should look like: cwebp input.png -q 80 -o output.webp which will convert the input file to a WebP file using a quality factor of 80 on a 0->100 scale (0 being the lowest quality, 100 being the best. Default value is 75). You might want to try the -lossless flag too, which will compress the source (in RGBA format) without any loss. The -q quality parameter will in this case control the amount of processing time spent trying to make the output file as small as possible.

A longer list of options is available using the -longhelp command line flag:

cwebp -longhelp Usage: cwebp [-preset <...>] [options] in_file [-o out_file]

If input size (-s) for an image is not specified, it is assumed to be a PNG, JPEG, TIFF or WebP file.

Options: -h / -help ............. short help -H / -longhelp ......... long help -q ............. quality factor (0:small..100:big), default=75 -alpha_q ......... transparency-compression quality (0..100), default=100 -preset ....... preset setting, one of: default, photo, picture, drawing, icon, text -preset must come first, as it overwrites other parameters -z ............... activates lossless preset with given level in [0:fast, ..., 9:slowest]

-m ............... compression method (0=fast, 6=slowest), default=4 -segments ........ number of segments to use (1..4), default=4 -size ............ target size (in bytes) -psnr .......... target PSNR (in dB. typically: 42)

Download Tool