First published: Wed Jan 08 2020(Updated: )
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nothings stb true type | <=1.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-6618.
The severity of CVE-2020-6618 is high.
CVE-2020-6618 manifests as a heap-based buffer over-read in stbtt__find_table in stb_truetype.h through version 1.22.
The software affected by CVE-2020-6618 is Nothings Stb Truetype.h version 1.22 and earlier.
At this time, there is no known fix for CVE-2020-6618. It is recommended to update to a newer version of the software if available.