OESA-2024-1230

    Dashboard / Vulnerabilities / OESA-2024-1230

    OESA-2024-1230

    Published: 1 Mar 2024Last Modified: 18 Aug 2026

    Summary: stb security update

    Details: Single-file public domain libraries for C/C++. Security Fix(es): stb_image is a single file MIT licensed library for processing images. When `stbi_set_flip_vertically_on_load` is set to `TRUE` and `req_comp` is set to a number that doesn’t match the real number of components per pixel, the library attempts to flip the image vertically. A crafted image file can trigger `memcpy` out-of-bounds read because `bytes_per_pixel` used to calculate `bytes_per_row` doesn’t match the real image array dimensions.(CVE-2023-45662) stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number of bytes from context (typically a file) into the specified buffer. In case the file stream points to the end, it returns zero. There are two places where its return value is not checked: In the `stbi__hdr_load` function and in the `stbi__tga_load` function. The latter of the two is likely more exploitable as an attacker may also control the size of an uninitialized buffer.(CVE-2023-45663)

    Affected packages

    Package

    Name: stb

    Purl: pkg:rpm/openEuler/stb&distro=openEuler-22.03-LTS-SP2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.20220908git8b5f1f3-0.10.oe2203sp2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2024-1230 | CVE-DB