5.8
CVSSv2

CVE-2021-42716

Published: 21/10/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.1 | Impact Score: 5.2 | Exploitability Score: 1.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

An issue exists in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nothings stb image.h 2.27

fedoraproject fedora 33

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Debian Bug report logs - #1014532 libstb: CVE-2021-42715 CVE-2021-42716 Package: src:libstb; Maintainer for src:libstb is Yangfl <mmyangfl@gmailcom>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 7 Jul 2022 15:45:06 UTC Severity: important Tags: security Reply or subscribe to this bug Toggle us ...