CVE-2018-16981
published 2018-09-12CVE-2018-16981: stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
PriorityP340high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.59%
72.9th percentile
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libstb | < libstb 0.0~git20190617.5.c72a95d-1 (bookworm) | libstb 0.0~git20190617.5.c72a95d-1 (bookworm) |
| nothings | stb_image.h | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
mame vulnerabilities
osv·2025-12-04·CVSS 8.8
CVE-2018-16981 [HIGH] mame vulnerabilities
mame vulnerabilities
It was discovered that the stb library, included in MAME, had a heap-based
buffer overflow. An attacker could possibly use this issue to crash the
program or execute arbitrary code. (CVE-2018-16981)
It was discovered that the tinyexr library, included in MAME, had a heap-
based buffer over-read in the function DecodePixelData. An attacker could
possibly use this issue to expose sensitive information or crash the
program. (CVE-2022-34300)
It was discovered that the expat library, included in MAME, had an
integer-overflow in the function doProlog. An attacker could possibly use
this issue to crash the program or execute arbitrary code.
(CVE-2021-46143)
GHSA
GHSA-5p8c-xff7-r336: stb stb_image
ghsa_unreviewed·2022-05-13
CVE-2018-16981 [HIGH] CWE-787 GHSA-5p8c-xff7-r336: stb stb_image
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
OSV
CVE-2018-16981: stb stb_image
osv·2018-09-12·CVSS 8.8
CVE-2018-16981 [HIGH] CVE-2018-16981: stb stb_image
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
Ubuntu
MAME vulnerabilities
vendor_ubuntu·2025-12-04·CVSS 8.8
CVE-2021-46143 [HIGH] MAME vulnerabilities
Title: MAME vulnerabilities
Summary: Several security issues were fixed in MAME.
It was discovered that the stb library, included in MAME, had a heap-based
buffer overflow. An attacker could possibly use this issue to crash the
program or execute arbitrary code. (CVE-2018-16981)
It was discovered that the tinyexr library, included in MAME, had a heap-
based buffer over-read in the function DecodePixelData. An attacker could
possibly use this issue to expose sensitive information or crash the
program. (CVE-2022-34300)
It was discovered that the expat library, included in MAME, had an
integer-overflow in the function doProlog. An attacker could possibly use
this issue to crash the program or execute arbitrary code.
(CVE-2021-46143)
Instructions: In general, a standard system update will
Red Hat
stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function
vendor_redhat·2018-09-12·CVSS 8.8
CVE-2018-16981 [HIGH] CWE-122 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function
stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
Statement: This issue did not affect the versions of cogl and compat-cogl114 as shipped with Red Hat Enterprise Linux 7.
This issue did not affect the versions of clutter as shipped with Red Hat Enterprise Linux 6.
Package: clutter (Red Hat Enterprise Linux 6) - Not affected
Package: cogl (Red Hat Enterprise Linux 7) - Not affected
Package: compat-cogl114 (Red Hat Enterprise Linux 7) - Not affected
Package: cogl (Red Hat Enterprise Linux 8) - Not affected
Package: SFML (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2018-16981: libstb - stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a h...
vendor_debian·2018·CVSS 8.8
CVE-2018-16981 [HIGH] CVE-2018-16981: libstb - stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a h...
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
Scope: local
bookworm: resolved (fixed in 0.0~git20190617.5.c72a95d-1)
bullseye: resolved (fixed in 0.0~git20190617.5.c72a95d-1)
forky: resolved (fixed in 0.0~git20190617.5.c72a95d-1)
sid: resolved (fixed in 0.0~git20190617.5.c72a95d-1)
trixie: resolved (fixed in 0.0~git20190617.5.c72a95d-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16981 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
bugzilla·2018-10-16·CVSS 8.8
CVE-2018-16981 [HIGH] CVE-2018-16981 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
CVE-2018-16981 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2018-16981 SFML: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
bugzilla·2018-10-16·CVSS 8.8
CVE-2018-16981 [HIGH] CVE-2018-16981 SFML: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
CVE-2018-16981 SFML: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2018-16981 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function
bugzilla·2018-10-16·CVSS 8.8
CVE-2018-16981 [HIGH] CVE-2018-16981 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function
CVE-2018-16981 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function
stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.
Upstream Issue:
https://github.com/nothings/stb/issues/656
Discussion:
Created SFML tracking bugs for this issue:
Affects: fedora-all [bug 1639552]
Created catimg tracking bugs for this issue:
Affects: fedora-all [bug 1639550]
Created cogl tracking bugs for this issue:
Affects: fedora-all [bug 1639551]
Created stbi tracking bugs for this issue:
Affects: fedora-all [bug 1639549]
---
the stbi versions bundled with clutter and cogl don't support gif loading.
---
Statement:
This issue did not affect the versions of cogl and compat-cogl114 as
Bugzilla
CVE-2018-16981 cogl: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
bugzilla·2018-10-16·CVSS 8.8
CVE-2018-16981 [HIGH] CVE-2018-16981 cogl: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
CVE-2018-16981 cogl: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue a
Bugzilla
CVE-2018-16981 catimg: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
bugzilla·2018-10-16·CVSS 8.8
CVE-2018-16981 [HIGH] CVE-2018-16981 catimg: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
CVE-2018-16981 catimg: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
2018-09-12
Published