Heap-Based Buffer Over-Read in stb Image Loader Affects Multiple Platforms
CVE-2019-15058
9.1CRITICAL
What is CVE-2019-15058?
The stb_image.h file, specifically version 2.23 of the stb image loader, is vulnerable to a heap-based buffer over-read in the stbi__tga_load function. This vulnerability poses significant risks, potentially allowing attackers to exploit this flaw for information disclosure or induce a denial of service attack. Because of this, users and systems relying on this library should assess their configurations and implement necessary updates or mitigations to safeguard against possible exploitation.