Bugzilla – Bug 1191944
VUL-1: CVE-2021-42716: stb: buffer overflow in stb_image PNM loader
Last modified: 2022-03-01 10:55:19 UTC
An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-42716 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42716 https://github.com/nothings/stb/issues/1225 https://github.com/nothings/stb/issues/1166 https://github.com/nothings/stb/pull/1223
Affected packages: - openSUSE:Backports:SLE-15-SP2/stb 2.32.1549563867.59e9702 - openSUSE:Backports:SLE-15-SP3/stb 2.32.1549563867.59e9702 - openSUSE:Backports:SLE-15-SP4/stb 2.32.1549563867.59e9702 - openSUSE:Factory/stb 2.36.1594640766.b42009b No new version released yet, but there are two github issues about it ([0], [1]) and a pull request [2]. Please update the packages to a new version when it becomes available. [0] https://github.com/nothings/stb/issues/1225 [1] https://github.com/nothings/stb/issues/1166 [2] https://github.com/nothings/stb/pull/1223
openSUSE-SU-2022:0157-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1191743,1191942,1191944 CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716 JIRA References: Sources used: openSUSE Leap 15.4 (src): zxing-cpp-1.2.0-9.7.1 openSUSE Leap 15.3 (src): zxing-cpp-1.2.0-9.7.1
SUSE-SU-2022:0157-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1191743,1191942,1191944 CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 15-SP3 (src): zxing-cpp-1.2.0-9.7.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): zxing-cpp-1.2.0-9.7.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:0163-1: An update that fixes three vulnerabilities is now available. Category: security (important) Bug References: 1191743,1191942,1191944 CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716 JIRA References: Sources used: SUSE Linux Enterprise Workstation Extension 12-SP5 (src): zxing-cpp-1.2.0-8.6.1 SUSE Linux Enterprise Software Development Kit 12-SP5 (src): zxing-cpp-1.2.0-8.6.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.