CVE-2018-16981Out-of-bounds Write in STB Image.h

Severity
8.8HIGHNVD
EPSS
0.5%
top 35.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 12
Latest updateDec 4

Description

stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages1 packages

Also affects: Debian Linux 10.0

🔴Vulnerability Details

4
OSV
mame vulnerabilities2025-12-04
GHSA
GHSA-5p8c-xff7-r336: stb stb_image2022-05-13
CVEList
CVE-2018-16981: stb stb_image2018-09-12
OSV
CVE-2018-16981: stb stb_image2018-09-12

📋Vendor Advisories

3
Ubuntu
MAME vulnerabilities2025-12-04
Red Hat
stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function2018-09-12
Debian
CVE-2018-16981: libstb - stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a h...2018

💬Community

5
Bugzilla
CVE-2018-16981 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]2018-10-16
Bugzilla
CVE-2018-16981 SFML: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]2018-10-16
Bugzilla
CVE-2018-16981 stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function2018-10-16
Bugzilla
CVE-2018-16981 cogl: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]2018-10-16
Bugzilla
CVE-2018-16981 catimg: stbi: Heap-based buffer overflow in stb_image.h:stbi__out_gif_code() function [fedora-all]2018-10-16
CVE-2018-16981 — Out-of-bounds Write in STB Image.h | cvebase