First published: Thu Mar 17 2022(Updated: )
** DISPUTED ** stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttUSHORT() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nothings stb true type | =1.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-25514.
The severity of CVE-2022-25514 is high with a score of 7.5.
The software affected by CVE-2022-25514 is stb_truetype.h version 1.26.
CVE-2022-25514 is a heap-buffer-overflow vulnerability in stb_truetype.h version 1.26, specifically in the ttUSHORT() function.
Yes, CVE-2022-25514 is disputed, with a third party claiming that the source code includes a disclaimer to only use it with trusted input.
Yes, you can find more information about CVE-2022-25514 at the following link: [https://github.com/nothings/stb/issues/1286](https://github.com/nothings/stb/issues/1286)
The CWE ID for CVE-2022-25514 is 787.