Description
stb_image is a single file MIT licensed library for processing images. A crafted image file may trigger out of bounds memcpy read in `stbi__gif_load_next`. This happens because two_back points to a memory address lower than the start of the buffer out. This issue may be used to leak internal memory allocation information.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49952 | stb_image is a single file MIT licensed library for processing images. A crafted image file may trigger out of bounds memcpy read in `stbi__gif_load_next`. This happens because two_back points to a memory address lower than the start of the buffer out. This issue may be used to leak internal memory allocation information. |
References
History
Thu, 13 Feb 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nothings stb Image
|
|
| CPEs | cpe:2.3:a:nothings:stb_image:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nothings stb Image
|
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-02-13T17:14:04.182Z
Reserved: 2023-10-10T14:36:40.859Z
Link: CVE-2023-45661
Updated: 2024-08-02T20:21:16.847Z
Status : Modified
Published: 2023-10-21T00:15:08.783
Modified: 2024-11-21T08:27:09.780
Link: CVE-2023-45661
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD