cbcvebase.
CVE-2021-37789
published 2022-11-02

CVE-2021-37789: stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

PriorityP336high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
0.78%
51.8th percentile
stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

Affected

3 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibstb< libstb 0.0~git20210910.af1a5bc+ds-1 (bookworm)libstb 0.0~git20210910.af1a5bc+ds-1 (bookworm)
stb_projectstb

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.