CVE-2021-37789
published 2022-11-02CVE-2021-37789: stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.
PriorityP336high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
0.78%
51.8th percentile
stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | libstb | < libstb 0.0~git20210910.af1a5bc+ds-1 (bookworm) | libstb 0.0~git20210910.af1a5bc+ds-1 (bookworm) |
| stb_project | stb | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
stb_image: heap-based buffer overflow
vendor_redhat·2022-11-09·CVSS 8.1
CVE-2021-37789 [HIGH] CWE-125 stb_image: heap-based buffer overflow
stb_image: heap-based buffer overflow
stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.
A flaw was found in stb_image. This issue occurs while processing the frame header information when the plane sampling configurations are calculated in two different ways, generating different results due to integer approximation. The value is further used to access several buffers, leading to a heap based out-of-bound read. This causes a heap data leak or an application crash, resulting in a denial of service.
Statement: Although the NVD CVSSv3.1 scoring point to a 8.1, Red Hat considers the impact to be Moderate as this flaw can not be used to perform arbitrary code execution, needs local access to be exploited, and the amount
Debian
CVE-2021-37789: libstb - stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Inf...
vendor_debian·2021·CVSS 8.1
CVE-2021-37789 [HIGH] CVE-2021-37789: libstb - stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Inf...
stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.
Scope: local
bookworm: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1)
bullseye: resolved (fixed in 0.0~git20200713.b42009b+ds-1+deb11u1)
forky: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1)
sid: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1)
trixie: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1)
OSV
CVE-2021-37789: stb_image
osv·2022-11-02·CVSS 8.1
CVE-2021-37789 [HIGH] CVE-2021-37789: stb_image
stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.
GHSA
GHSA-3fjh-5fm6-fqmw: stb_image
ghsa_unreviewed·2022-11-02
CVE-2021-37789 [HIGH] CWE-787 GHSA-3fjh-5fm6-fqmw: stb_image
stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-02
Published