CVE-2021-42716

An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nothings:stb_image.h:2.27:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-10-21 19:15

Updated : 2023-11-07 03:39


NVD link : CVE-2021-42716

Mitre link : CVE-2021-42716

CVE.ORG link : CVE-2021-42716


JSON object : View

Products Affected

fedoraproject

  • fedora

nothings

  • stb_image.h
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')