PT-2022-7205 · Unknown+3 · Stb Image.H+3

Nbickford-Nv

·

Published

2022-02-17

·

Updated

2023-02-23

·

CVE-2022-28042

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Libstb versions prior to the version with the fixed stb image.h component stb image.h version 2.27
Description The issue is related to a heap-based use-after-free in the stb image.h component of the Libstb library for C/C++. This can be exploited by a remote attacker to access confidential data, compromise data integrity, and cause a denial of service. The vulnerability is specifically found in the stbi jpeg huff decode function.
Recommendations For stb image.h version 2.27, consider disabling the stbi jpeg huff decode function until a patch is available. For Libstb, update to a version that includes the fixed stb image.h component to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2023-09088
CVE-2022-28042
DLA-3305-1

Affected Products

Astra Linux
Debian
Libstb
Stb Image.H