cbcvebase.

Debian Libstb vulnerabilities

18 known vulnerabilities affecting debian/libstb.

Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM6LOW2

Vulnerabilities

Page 1 of 1
CVE-2019-15058P3CRITICALCVSS 9.1fixed in libstb 0.0~git20210910.af1a5bc+ds-1 (bookworm)2019
CVE-2019-15058 [CRITICAL] CVE-2019-15058: libstb - stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in... stb_image.h (aka the stb image loader) 2.23 has a heap-based buffer over-read in stbi__tga_load, leading to Information Disclosure or Denial of Service. Scope: local bookworm: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1) bullseye: open forky: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1) sid: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1) trixie: resolve
debian
CVE-2022-28042P3HIGHCVSS 8.8fixed in libstb 0.0~git20200713.b42009b+ds-1+deb11u1 (bullseye)2022
CVE-2022-28042 [HIGH] CVE-2022-28042: libstb - stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the... stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. Scope: local bookworm: open bullseye: resolved (fixed in 0.0~git20200713.b42009b+ds-1+deb11u1) forky: resolved (fixed in 0.0~git20230129.5736b15+ds-1) sid: resolved (fixed in 0.0~git20230129.5736b15+ds-1) trixie: resolved (fixed in 0.0~git20230129.5736b15
debian
CVE-2018-16981P3HIGHCVSS 8.8fixed in libstb 0.0~git20190617.5.c72a95d-1 (bookworm)2018
CVE-2018-16981 [HIGH] CVE-2018-16981: libstb - stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a h... stb stb_image.h 2.19, as used in catimg, Emscripten, and other products, has a heap-based buffer overflow in the stbi__out_gif_code function. Scope: local bookworm: resolved (fixed in 0.0~git20190617.5.c72a95d-1) bullseye: resolved (fixed in 0.0~git20190617.5.c72a95d-1) forky: resolved (fixed in 0.0~git20190617.5.c72a95d-1) sid: resolved (fixed in 0.0~git20190617.5.c
debian
CVE-2022-28048P3LOWCVSS 8.8fixed in libstb 0.0~git20230129.5736b15+ds-1 (forky)2022
CVE-2022-28048 [HIGH] CVE-2022-28048: libstb - STB v2.27 was discovered to contain an integer shift of invalid size in the comp... STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 0.0~git20230129.5736b15+ds-1) sid: resolved (fixed in 0.0~git20230129.5736b15+ds-1) trixie: resolved (fixed in 0.0~git20230129.5736b15+ds-1)
debian
CVE-2021-37789P3HIGHCVSS 8.1fixed in libstb 0.0~git20210910.af1a5bc+ds-1 (bookworm)2021
CVE-2021-37789 [HIGH] CVE-2021-37789: libstb - stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Inf... stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service. Scope: local bookworm: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1) bullseye: resolved (fixed in 0.0~git20200713.b42009b+ds-1+deb11u1) forky: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1) sid: resolved (fixed in 0.0~git20210910.af1a5bc+ds-1
debian
CVE-2019-13217P3HIGHCVSS 7.8fixed in libstb 0.0~git20190817.1.052dce1-1 (bookworm)2019
CVE-2019-13217 [HIGH] CVE-2019-13217: libstb - A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-... A heap buffer overflow in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file. Scope: local bookworm: resolved (fixed in 0.0~git20190817.1.052dce1-1) bullseye: resolved (fixed in 0.0~git20190817.1.052dce1-1) forky: resolved (fixed in 0.0~git20190817.
debian
CVE-2019-13221P3HIGHCVSS 7.8fixed in libstb 0.0~git20190817.1.052dce1-1 (bookworm)2019
CVE-2019-13221 [HIGH] CVE-2019-13221: libstb - A stack buffer overflow in the compute_codewords function in stb_vorbis through ... A stack buffer overflow in the compute_codewords function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or execute arbitrary code by opening a crafted Ogg Vorbis file. Scope: local bookworm: resolved (fixed in 0.0~git20190817.1.052dce1-1) bullseye: resolved (fixed in 0.0~git20190817.1.052dce1-1) forky: resolved (fixed in 0.0~git2019
debian
CVE-2021-28021P4HIGHCVSS 7.8fixed in libstb 0.0~git20220908.8b5f1f3+ds-1 (bookworm)2021
CVE-2021-28021 [HIGH] CVE-2021-28021: libstb - Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in... Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file. Scope: local bookworm: resolved (fixed in 0.0~git20220908.8b5f1f3+ds-1) bullseye: resolved (fixed in 0.0~git20200713.b42009b+ds-1+deb11u1) forky: resolved (fixed in 0.0~git20220908.8b5f1f3+ds-1) sid: resolved (fixed in 0.0~git20220908.8b5f1f3+ds-1) trixi
debian
CVE-2021-42716P4HIGHCVSS 7.1fixed in libstb 0.0~git20230129.5736b15+ds-1 (forky)2021
CVE-2021-42716 [HIGH] CVE-2021-42716: libstb - An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly inte... An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over
debian
CVE-2022-28041P4MEDIUMCVSS 6.5fixed in libstb 0.0~git20200713.b42009b+ds-1+deb11u1 (bullseye)2022
CVE-2022-28041 [MEDIUM] CVE-2022-28041: libstb - stb_image.h v2.27 was discovered to contain an integer overflow via the function... stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. Scope: local bookworm: open bullseye: resolved (fixed in 0.0~git20200713.b42009b+ds-1+deb11u1) forky: resolved (fixed in 0.0~git20230129.5736b15+ds-1) sid: r
debian
CVE-2019-13220P4HIGHCVSS 7.1fixed in libstb 0.0~git20190817.1.052dce1-1 (bookworm)2019
CVE-2019-13220 [HIGH] CVE-2019-13220: libstb - Use of uninitialized stack variables in the start_decoder function in stb_vorbis... Use of uninitialized stack variables in the start_decoder function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file. Scope: local bookworm: resolved (fixed in 0.0~git20190817.1.052dce1-1) bullseye: resolved (fixed in 0.0~git20190817.1.052dce1-1) forky: resolved (fix
debian
CVE-2019-13222P4HIGHCVSS 7.1fixed in libstb 0.0~git20190817.1.052dce1-1 (bookworm)2019
CVE-2019-13222 [HIGH] CVE-2019-13222: libstb - An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis... An out-of-bounds read of a global buffer in the draw_line function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service or disclose sensitive information by opening a crafted Ogg Vorbis file. Scope: local bookworm: resolved (fixed in 0.0~git20190817.1.052dce1-1) bullseye: resolved (fixed in 0.0~git20190817.1.052dce1-1) forky: resolved (fix
debian
CVE-2019-20056P4LOWCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20056 [MEDIUM] CVE-2019-20056: libsixel - stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other produ... stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned. Scope: local bookworm: resolved (fixed in 1.8.6-1) bullseye: resolved (fixed in 1.8.6-1) forky: resolved (fixed in 1.8.6-1) sid: resolved (fixed in 1.8.6-1) trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2021-45340P4MEDIUMCVSS 6.5fixed in libsixel 1.10.5-1 (forky)2021
CVE-2021-45340 [MEDIUM] CVE-2021-45340: libsixel - In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the st... In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file. Scope: local bookworm: open bullseye: open forky: resolved (fixed in 1.10.5-1) sid: resolved (fixed in 1.10.5-1) trixie: resolved (fixed in 1.10.5-1)
debian
CVE-2021-42715P4MEDIUMCVSS 5.5fixed in libstb 0.0~git20200713.b42009b+ds-1+deb11u1 (bullseye)2021
CVE-2021-42715 [MEDIUM] CVE-2021-42715: libstb - An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader par... An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files. Scope: local bookworm: open bullseye: resolved (fixed in 0.0~git20200713.b420
debian
CVE-2019-13218P4MEDIUMCVSS 5.5fixed in libstb 0.0~git20190817.1.052dce1-1 (bookworm)2019
CVE-2019-13218 [MEDIUM] CVE-2019-13218: libstb - Division by zero in the predict_point function in stb_vorbis through 2019-03-04 ... Division by zero in the predict_point function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. Scope: local bookworm: resolved (fixed in 0.0~git20190817.1.052dce1-1) bullseye: resolved (fixed in 0.0~git20190817.1.052dce1-1) forky: resolved (fixed in 0.0~git20190817.1.052dce1-1) sid: resolved (fi
debian
CVE-2019-13223P4MEDIUMCVSS 5.5fixed in libstb 0.0~git20190817.1.052dce1-1 (bookworm)2019
CVE-2019-13223 [MEDIUM] CVE-2019-13223: libstb - A reachable assertion in the lookup1_values function in stb_vorbis through 2019-... A reachable assertion in the lookup1_values function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. Scope: local bookworm: resolved (fixed in 0.0~git20190817.1.052dce1-1) bullseye: resolved (fixed in 0.0~git20190817.1.052dce1-1) forky: resolved (fixed in 0.0~git20190817.1.052dce1-1) sid: resolv
debian
CVE-2019-13219P4MEDIUMCVSS 5.5fixed in libstb 0.0~git20190817.1.052dce1-1 (bookworm)2019
CVE-2019-13219 [MEDIUM] CVE-2019-13219: libstb - A NULL pointer dereference in the get_window function in stb_vorbis through 2019... A NULL pointer dereference in the get_window function in stb_vorbis through 2019-03-04 allows an attacker to cause a denial of service by opening a crafted Ogg Vorbis file. Scope: local bookworm: resolved (fixed in 0.0~git20190817.1.052dce1-1) bullseye: resolved (fixed in 0.0~git20190817.1.052dce1-1) forky: resolved (fixed in 0.0~git20190817.1.052dce1-1) sid: resol
debian
Debian Libstb vulnerabilities | cvebase