Impact
The vulnerability is an out-of-bounds read in the function stbtt_InitFont_internal of the stb_truetype.h header in the Nothings stb library. An attacker can manipulate a TrueType font file to trigger the out-of-bounds read, potentially allowing remote exploitation. The description indicates that remote exploitation is possible, raising the risk of compromise of confidentiality, integrity, and availability of systems processing malicious font files.
Affected Systems
The issue affects the Nothings stb library up to and including version 1.26. Users of this library should verify whether their deployments rely on these versions and consider upgrading to a fixed release if one becomes available.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium severity range. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves a remote adversary delivering a crafted TTF file to an application that uses the vulnerable library, such as a graphic viewer or web browser that renders fonts.
OpenCVE Enrichment