Bug 1191944 - (CVE-2021-42716) VUL-1: CVE-2021-42716: stb: buffer overflow in stb_image PNM loader
(CVE-2021-42716)
VUL-1: CVE-2021-42716: stb: buffer overflow in stb_image PNM loader
Status: NEW
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.3
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Adrian Schröter
Security Team bot
https://smash.suse.de/issue/313286/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-10-22 07:40 UTC by Gabriele Sonnu
Modified: 2022-03-01 10:55 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Gabriele Sonnu 2021-10-22 07:40:04 UTC
An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly
interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a
buffer overflow when later reinterpreting the result as a 16-bit buffer. An
attacker could potentially have crashed a service using stb_image, or read up to
1024 bytes of non-consecutive heap data without control over the read location.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-42716
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-42716
https://github.com/nothings/stb/issues/1225
https://github.com/nothings/stb/issues/1166
https://github.com/nothings/stb/pull/1223
Comment 1 Gabriele Sonnu 2021-10-22 07:43:14 UTC
Affected packages:

 - openSUSE:Backports:SLE-15-SP2/stb  2.32.1549563867.59e9702
 - openSUSE:Backports:SLE-15-SP3/stb  2.32.1549563867.59e9702
 - openSUSE:Backports:SLE-15-SP4/stb  2.32.1549563867.59e9702
 - openSUSE:Factory/stb               2.36.1594640766.b42009b

No new version released yet, but there are two github issues about it ([0], [1]) and a pull request [2].
Please update the packages to a new version when it becomes available.

[0] https://github.com/nothings/stb/issues/1225
[1] https://github.com/nothings/stb/issues/1166
[2] https://github.com/nothings/stb/pull/1223
Comment 3 Swamp Workflow Management 2022-01-24 14:21:11 UTC
openSUSE-SU-2022:0157-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1191743,1191942,1191944
CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716
JIRA References: 
Sources used:
openSUSE Leap 15.4 (src):    zxing-cpp-1.2.0-9.7.1
openSUSE Leap 15.3 (src):    zxing-cpp-1.2.0-9.7.1
Comment 4 Swamp Workflow Management 2022-01-24 14:22:38 UTC
SUSE-SU-2022:0157-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1191743,1191942,1191944
CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 15-SP3 (src):    zxing-cpp-1.2.0-9.7.1
SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src):    zxing-cpp-1.2.0-9.7.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2022-01-24 17:19:20 UTC
SUSE-SU-2022:0163-1: An update that fixes three vulnerabilities is now available.

Category: security (important)
Bug References: 1191743,1191942,1191944
CVE References: CVE-2021-28021,CVE-2021-42715,CVE-2021-42716
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 12-SP5 (src):    zxing-cpp-1.2.0-8.6.1
SUSE Linux Enterprise Software Development Kit 12-SP5 (src):    zxing-cpp-1.2.0-8.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.