CVE-2022-28048
published 2022-04-15CVE-2022-28048: STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
PriorityP340high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.56%
72.4th percentile
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libstb | < libstb 0.0~git20230129.5736b15+ds-1 (forky) | libstb 0.0~git20230129.5736b15+ds-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| stb_project | stb | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hh7c-jpm3-846q: STB v2
ghsa_unreviewed·2022-04-16
CVE-2022-28048 [HIGH] CWE-682 GHSA-hh7c-jpm3-846q: STB v2
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
OSV
CVE-2022-28048: STB v2
osv·2022-04-15·CVSS 8.8
CVE-2022-28048 [HIGH] CVE-2022-28048: STB v2
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
Red Hat
stb: integer shift of invalid size in stbi__jpeg_decode_block_prog_ac()
vendor_redhat·2022-02-17·CVSS 8.8
CVE-2022-28048 [HIGH] CWE-190 stb: integer shift of invalid size in stbi__jpeg_decode_block_prog_ac()
stb: integer shift of invalid size in stbi__jpeg_decode_block_prog_ac()
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
Statement: This flaw does not affect the versions of cogl shipped with Red Hat Enterprise Linux 7 or 8 because the affected code is not shipped in those packages. This flaw is out of support scope for Red Hat Enterprise Linux 6.
Package: clutter (Red Hat Enterprise Linux 6) - Out of support scope
Package: cogl (Red Hat Enterprise Linux 7) - Not affected
Package: compat-cogl114 (Red Hat Enterprise Linux 7) - Not affected
Package: cogl (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2022-28048: libstb - STB v2.27 was discovered to contain an integer shift of invalid size in the comp...
vendor_debian·2022·CVSS 8.8
CVE-2022-28048 [HIGH] CVE-2022-28048: libstb - STB v2.27 was discovered to contain an integer shift of invalid size in the comp...
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 0.0~git20230129.5736b15+ds-1)
sid: resolved (fixed in 0.0~git20230129.5736b15+ds-1)
trixie: resolved (fixed in 0.0~git20230129.5736b15+ds-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/nothings/stb/issues/1293https://github.com/nothings/stb/pull/1297https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FXLM5XL77SNH4IPTSXOQD7XL4E2EMIN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I4HXIWU5HBOADXZVMREHT4YTO5WVYXEQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MMBCMJGAZRQS55SNECUWZSC5URVLEZ5R/https://github.com/nothings/stb/issues/1293https://github.com/nothings/stb/pull/1297https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FXLM5XL77SNH4IPTSXOQD7XL4E2EMIN/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I4HXIWU5HBOADXZVMREHT4YTO5WVYXEQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MMBCMJGAZRQS55SNECUWZSC5URVLEZ5R/
2022-04-15
Published