PT-2026-102961 · Stb · Stb
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Nothings stb versions prior to 1.17
Description
A flaw in the Image Encoding component of the
stb image write.h library allows for a remote attack. The issue resides in the stbi write png to mem(), stbi write jpg core(), and stbi write tga core() functions, where a manipulation can lead to an integer overflow, a condition where an arithmetic operation results in a value that exceeds the storage capacity of the integer type.Recommendations
Update Nothings stb to version 1.17 or later.
As a temporary workaround, restrict the use of the
stbi write png to mem(), stbi write jpg core(), and stbi write tga core() functions.Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Stb