CVE Feed

    Dashboard / CVE / CVE-2021-42716

    CVE-2021-42716

    An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.

    Published:Jul 14, 2021
    Last Modified:Nov 21, 2024
    EPS:Oct 21, 2021
    EPSS Score:0.0025
    CVSS Score:7.1

    Affected Products

    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Nothings
    Product
    Stb Image.h

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High