An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.
References
Configurations
History
13 May 2022, 17:25
Type | Values Removed | Values Added |
---|---|---|
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXX76TJMZBPN3NU542MGN6B7C7QHRFGB/ - Mailing List, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 5.8
v3 : 7.1 |
29 Apr 2022, 09:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 Nov 2021, 20:59
Type | Values Removed | Values Added |
---|---|---|
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ID6II3RIKAMVGVMC6ZAQIXXYYDMTVC4N/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BEGXBDEMTFGINETMJENBZ6SCHVEJQJSY/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VP2YEXEAJWI76FPM7D7VXHWD3WESQEYC/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G2M5CRSGPRF7G3YB5CLU4FXW7ANNHAYT/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AF2CNP4FVC6LDKNOO4WDCGNDYIP3MPK6/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3TDGZFLBOP27LZKLH45WQLSNPSPP7S7Z/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FTZXHFZD36BGE5P6JF252NZZLKMGCY4T/ - Mailing List, Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CI23LXPEV2GCDQTJSKO6CIILBDTI3R42/ - Mailing List, Third Party Advisory | |
CPE | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* |
17 Nov 2021, 22:19
Type | Values Removed | Values Added |
---|---|---|
References |
|
10 Nov 2021, 01:19
Type | Values Removed | Values Added |
---|---|---|
References |
|
03 Nov 2021, 04:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
02 Nov 2021, 04:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Nov 2021, 06:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
31 Oct 2021, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Oct 2021, 22:34
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-120 | |
CPE | cpe:2.3:a:nothings:stb_image.h:2.27:*:*:*:*:*:*:* | |
References | (MISC) https://github.com/nothings/stb/issues/1225 - Exploit, Issue Tracking, Third Party Advisory | |
References | (MISC) https://github.com/nothings/stb/pull/1223 - Third Party Advisory | |
References | (MISC) https://github.com/nothings/stb/issues/1166 - Exploit, Issue Tracking, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : 6.4
v3 : 9.1 |
21 Oct 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-10-21 19:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-42716
Mitre link : CVE-2021-42716
CVE.ORG link : CVE-2021-42716
JSON object : View
Products Affected
nothings
- stb_image.h
fedoraproject
- fedora
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')