Bug 2246104 (CVE-2023-45663) - CVE-2023-45663 stb: memory access violations
Summary: CVE-2023-45663 stb: memory access violations
Keywords:
Status: NEW
Alias: CVE-2023-45663
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2246106 2246107 2246108
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-10-25 13:04 UTC by ybuenos
Modified: 2023-10-26 01:01 UTC (History)
0 users

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description ybuenos 2023-10-25 13:04:23 UTC
stb_image is a single file MIT licensed library for processing images. The stbi__getn function reads a specified number of bytes from context (typically a file) into the specified buffer. In case the file stream points to the end, it returns zero. There are two places where its return value is not checked: In the `stbi__hdr_load` function and in the `stbi__tga_load` function. The latter of the two is likely more exploitable as an attacker may also control the size of an uninitialized buffer.

https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_image.h#L5936C10-L5936C20
https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_image.h#L7221
https://github.com/nothings/stb/blob/5736b15f7ea0ffb08dd38af21067c314d6a3aae9/stb_image.h#L1664
https://securitylab.github.com/advisories/GHSL-2023-145_GHSL-2023-151_stb_image_h/

Comment 1 ybuenos 2023-10-25 13:06:55 UTC
Created assimp tracking bugs for this issue:

Affects: epel-8 [bug 2246108]


Created stb tracking bugs for this issue:

Affects: epel-all [bug 2246107]
Affects: fedora-all [bug 2246106]

Comment 2 Fedora Update System 2023-10-26 01:01:16 UTC
FEDORA-2023-58af3a2eca has been pushed to the Fedora 40 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.