Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-45663

Опубликовано: 21 окт. 2023
Источник: nvd
CVSS3: 5.3
CVSS3: 5.5
EPSS Низкий

Описание

stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number of bytes from context (typically a file) into the specified buffer. In case the file stream points to the end, it returns zero. There are two places where its return value is not checked: In the stbi__hdr_load function and in the stbi__tga_load function. The latter of the two is likely more exploitable as an attacker may also control the size of an uninitialized buffer.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:nothings:stb_image.h:2.28:*:*:*:*:*:*:*

EPSS

Процентиль: 35%
0.00143
Низкий

5.3 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-908
CWE-908

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number of bytes from context (typically a file) into the specified buffer. In case the file stream points to the end, it returns zero. There are two places where its return value is not checked: In the `stbi__hdr_load` function and in the `stbi__tga_load` function. The latter of the two is likely more exploitable as an attacker may also control the size of an uninitialized buffer.

CVSS3: 5.3
debian
больше 2 лет назад

stb_image is a single file MIT licensed library for processing images. ...

EPSS

Процентиль: 35%
0.00143
Низкий

5.3 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-908
CWE-908