Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-37789

Опубликовано: 09 нояб. 2022
Источник: redhat
CVSS3: 8.1

Описание

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

A flaw was found in stb_image. This issue occurs while processing the frame header information when the plane sampling configurations are calculated in two different ways, generating different results due to integer approximation. The value is further used to access several buffers, leading to a heap based out-of-bound read. This causes a heap data leak or an application crash, resulting in a denial of service.

Отчет

Although the NVD CVSSv3.1 scoring point to a 8.1, Red Hat considers the impact to be Moderate as this flaw can not be used to perform arbitrary code execution, needs local access to be exploited, and the amount of leaked information is constrained to a few bytes within the process heap.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6clutterOut of support scope
Red Hat Enterprise Linux 7coglOut of support scope
Red Hat Enterprise Linux 7compat-cogl114Out of support scope
Red Hat Enterprise Linux 8coglWill not fix
Red Hat Enterprise Linux 9coglWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2141433stb_image: heap-based buffer overflow

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
больше 3 лет назад

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

CVSS3: 8.1
nvd
больше 3 лет назад

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

CVSS3: 8.1
debian
больше 3 лет назад

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, lead ...

CVSS3: 8.1
github
больше 3 лет назад

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

CVSS3: 8.1
fstec
больше 4 лет назад

Уязвимость компонента stb_image.h библиотек для C/C++ Libstb, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

8.1 High

CVSS3