Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian LTS: DLA-3305-1 Urgent Libstb Memory Vulnerability Report

debian lts
Calendar Grey January 31, 2023
Dist Debian Esm H88
Numerous security flaws in the libstb package addressed in Debian LTS Advisory DLA-3305-2. Immediate upgrade advised for protection.
Several vulnerabilities have been fixed in the libstb library

Summary

CVE-2018-16981

Heap-based buffer overflow in stbi__out_gif_code().

CVE-2019-13217

Heap buffer overflow in the Vorbis start_decoder().

CVE-2019-13218

Division by zero in the Vorbis predict_point().

CVE-2019-13219

NULL pointer dereference in the Vorbis get_window().

CVE-2019-13220

Uninitialized stack variables in the Vorbis start_decoder().

CVE-2019-13221

Buffer overflow in the Vorbis compute_codewords().

CVE-2019-13222

Out-of-bounds read of a global buffer in the Vorbis draw_line().

CVE-2019-13223

Reachable assertion in the Vorbis lookup1_values().

CVE-2021-28021

Buffer overflow in stbi__extend_receive().

CVE-2021-37789

Heap-based buffer overflow in stbi__jpeg_load().

CVE-2021-42715

The HDR loader parsed truncated end-of-file RLE scanlines as an
infinite sequence of zero-length runs.

CVE-2022-28041

Integer overflow in stbi__jpeg_decode_block_prog_dc().

CVE-2022-28042

Heap-based use-after-free in stbi__jpeg_huff_decode().

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: libstb
Version: 0.0~git20180212.15.e6afb9c-1+deb10u1
CVE ID: CVE-2018-16981 CVE-2019-13217 CVE-2019-13218 CVE-2019-13219
Debian Bug: 934966 1014530 1023693 1014531 1014532

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here