CVE-2021-42715
Gentoo Linux Security Advisory 202409-15
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.
Se ha detectado un problema en stb stb_image.h versiones 1.33 hasta 2.27. El cargador HDR analizaba líneas de exploración RLE truncadas al final del archivo como una secuencia infinita de ejecuciones de longitud cero. Un atacante podría haber causado potencialmente una denegación de servicio en las aplicaciones usando stb_image al enviar archivos HDR diseñados
An update that fixes three vulnerabilities is now available. This update for zxing-cpp fixes the following issues. Fixed buffer overflow vulnerability in function stbi__extend_receive in stb_image.h via a crafted JPEG file. Fixed buffer overflow in stb_image PNM loader. Fixed denial of service in stb_image HDR loader when reading crafted HDR files.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-19 CVE Reserved
- 2021-10-21 CVE Published
- 2024-08-04 CVE Updated
- 2025-04-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
https://github.com/nothings/stb/issues/1224 | Issue Tracking | |
https://github.com/nothings/stb/pull/1223 | Third Party Advisory | |
https://lists.debian.org/debian-lts-announce/2023/01/msg00045.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nothings Search vendor "Nothings" | Stb Image.h Search vendor "Nothings" for product "Stb Image.h" | >= 1.33 <= 2.27 Search vendor "Nothings" for product "Stb Image.h" and version " >= 1.33 <= 2.27" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 33 Search vendor "Fedoraproject" for product "Fedora" and version "33" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 35 Search vendor "Fedoraproject" for product "Fedora" and version "35" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|