CVE-2019-15058Out-of-bounds Read in Libstb

Severity
9.1CRITICALNVD
EPSS
1.2%
top 21.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 24

Description

stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

debiandebian/libstb< libstb 0.0~git20210910.af1a5bc+ds-1 (bookworm)
NVDstb_project/stb2.23

🔴Vulnerability Details

2
GHSA
GHSA-77mw-2mfc-5cxm: stb_image2022-05-24
OSV
CVE-2019-15058: stb_image2019-08-14

📋Vendor Advisories

2
Red Hat
stbi: heap-based buffer overflow in stbi__tga_load function in stb_image.h2019-08-13
Debian
CVE-2019-15058: libstb - stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in...2019

💬Community

2
Bugzilla
CVE-2019-15058 stbi: heap-based buffer overflow in stbi__tga_load function in stb_image.h2020-03-23
Bugzilla
CVE-2019-15058 stbi: heap-based buffer overflow in stbi__tga_load function in stb_image.h [fedora-all]2020-03-23