Heap-Based Buffer Over-Read in stb_truetype.h Affects stb by nothings
CVE-2020-6622
8.8HIGH
What is CVE-2020-6622?
The stb library, specifically the stb_truetype.h file before version 1.22, is vulnerable to a heap-based buffer over-read identified in the function stbtt__buf_peek8. This vulnerability could lead to unintended memory disclosure, enhancing opportunities for potential exploitation in applications that utilize the affected versions.
