PT-2022-7204 · Unknown+2 · Stb Image.H+2

Nbickford-Nv

·

Published

2022-02-17

·

Updated

2024-03-25

·

CVE-2022-28041

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions stb image.h version 2.27
Description The issue is related to an integer overflow in the stbi jpeg decode block prog dc function, which can be exploited by attackers to cause a Denial of Service (DoS) via unspecified vectors. This can allow a remote attacker to disrupt the service.
Recommendations For stb image.h version 2.27, consider disabling the stbi jpeg decode block prog dc function as a temporary workaround until a patch is available. Restrict access to the stb image.h library to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-09087
CVE-2022-28041
DLA-3305-1
MGASA-2023-0228
MGASA-2024-0088

Affected Products

Astra Linux
Debian
Stb Image.H