CVE-2021-42716

NameCVE-2021-42716
DescriptionAn issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1014532

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libstb (PTS)buster (security), buster, buster (lts)0.0~git20180212.15.e6afb9c-1+deb10u1fixed
bullseye0.0~git20200713.b42009b+ds-1fixed
bookworm0.0~git20220908.8b5f1f3+ds-1vulnerable
sid, trixie0.0~git20240715.f7f20f39fe4f+ds-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libstbsourcebuster(not affected)
libstbsourcebullseye(not affected)
libstbsource(unstable)0.0~git20230129.5736b15+ds-11014532

Notes

[bookworm] - libstb <no-dsa> (Minor issue)
[bullseye] - libstb <not-affected> (Vulnerable code introduced later)
[buster] - libstb <not-affected> (Vulnerable code introduced later)
https://github.com/nothings/stb/issues/1166
https://github.com/nothings/stb/issues/1225
https://github.com/nothings/stb/pull/1223
16-bin PNM support was added in
https://github.com/nothings/stb/commit/8befa752b005da174b2429c1ffaafffe452b2997

Search for package or bug name: Reporting problems