Bugzilla – Bug 1191942
VUL-1: CVE-2021-42715: stb: denial of service in stb_image HDR loader when reading crafted HDR files
Last modified: 2022-09-28 12:36:44 UTC
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-42715 https://github.com/nothings/stb/pull/1223 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42715 https://github.com/nothings/stb/issues/1224
Affected packages: - openSUSE:Backports:SLE-15-SP2/stb 2.32.1549563867.59e9702 - openSUSE:Backports:SLE-15-SP3/stb 2.32.1549563867.59e9702 - openSUSE:Backports:SLE-15-SP4/stb 2.32.1549563867.59e9702 - openSUSE:Factory/stb 2.36.1594640766.b42009b No new version released yet, but there is ongoing discussion in the github issue [0] and a pull request [1]. Please update the packages to a new version when it becomes available. [0] https://github.com/nothings/stb/issues/1224 [1] https://github.com/nothings/stb/pull/1223
openSUSE-SU-2022:0157-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1191743,1191942,1191944 CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716 JIRA References: Sources used: openSUSE Leap 15.4 (src): zxing-cpp-1.2.0-9.7.1 openSUSE Leap 15.3 (src): zxing-cpp-1.2.0-9.7.1
SUSE-SU-2022:0157-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1191743,1191942,1191944 CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 15-SP3 (src): zxing-cpp-1.2.0-9.7.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): zxing-cpp-1.2.0-9.7.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:0163-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1191743,1191942,1191944 CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 12-SP5 (src): zxing-cpp-1.2.0-8.6.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): zxing-cpp-1.2.0-8.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.