First published: Wed Jan 08 2020(Updated: )
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nothings stb true type | <=1.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6620 is a vulnerability in the stb_truetype.h library, version 1.22, that allows for a heap-based buffer over-read.
The severity of CVE-2020-6620 is high with a CVSS score of 8.8.
CVE-2020-6620 affects software that uses the stb_truetype.h library, version 1.22.
To fix CVE-2020-6620, update to a version of stb_truetype.h library that is not affected, if available.
More information about CVE-2020-6620 can be found at the following reference: https://github.com/nothings/stb/issues/868