Impact
A flaw in Nothings' stb image library up to version 1.16 can cause an integer overflow when encoding PNG, JPG, or TGA images. The overflow occurs in the stbi_write_* core functions of stb_image_write.h and can corrupt memory or overwrite critical data. This vulnerability can be triggered remotely by providing a crafted image, and published exploits may already be available, potentially allowing arbitrary code execution or denial of service.
Affected Systems
Nothings’ stb image library, all releases up to and including version 1.16. No specific sub‑versions are enumerated, so any build of stb prior to the next released version is considered vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity, but the lack of an EPSS score means the probability of exploitation is currently uncertain. The vulnerability is remotely exploitable without authentication and is not listed in the CISA KEV catalog. Since published exploits exist, this risk is compounded, and attackers can potentially abuse the integer overflow to achieve arbitrary memory writes or code execution with suitable crafted inputs.
OpenCVE Enrichment