CVE-2023-45661
21.10.2023, 00:15
stb_image is a single file MIT licensed library for processing images. A crafted image file may trigger out of bounds memcpy read in `stbi__gif_load_next`. This happens because two_back points to a memory address lower than the start of the buffer out. This issue may be used to leak internal memory allocation information.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nothings | stb_image.h | 2.28 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| nothings | stb_image | 𝑥 ≤ 2.28 | ADP |
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References