Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2021-37789
HistoryNov 02, 2022 - 1:15 p.m.

CVE-2021-37789

2022-11-0213:15:10
Debian Security Bug Tracker
security-tracker.debian.org
10
stb_image.h 2.27 heap-based buffer overflow
stbi__jpeg_load
information disclosure
denial of service
unix

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

EPSS

0.002

Percentile

60.1%

stb_image.h 2.27 has a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service.

OSVersionArchitecturePackageVersionFilename
Debian12alllibstb< 0.0~git20210910.af1a5bc+ds-1libstb_0.0~git20210910.af1a5bc+ds-1_all.deb
Debian11alllibstb<= 0.0~git20200713.b42009b+ds-1libstb_0.0~git20200713.b42009b+ds-1_all.deb
Debian999alllibstb< 0.0~git20210910.af1a5bc+ds-1libstb_0.0~git20210910.af1a5bc+ds-1_all.deb
Debian13alllibstb< 0.0~git20210910.af1a5bc+ds-1libstb_0.0~git20210910.af1a5bc+ds-1_all.deb

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

EPSS

0.002

Percentile

60.1%