CVE-2022-25515: Medium severity nothings stb true type vulnerability
DISPUTED stbtruetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stbtruetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25515?
CVE-2022-25515 is a heap buffer overflow vulnerability in stb_truetype.h v1.26.
What is the severity of CVE-2022-25515?
The severity of CVE-2022-25515 is medium with a CVSS score of 6.5.
How does CVE-2022-25515 affect stb_truetype.h?
CVE-2022-25515 affects stb_truetype.h v1.26.
Are there any available patches or fixes for CVE-2022-25515?
At the moment, there are no official patches or fixes available for CVE-2022-25515. It is recommended to follow the latest updates and mitigation strategies provided by the vendor or software developer.
Where can I find more information about CVE-2022-25515?
You can find more information about CVE-2022-25515 at the following references: [GitHub Issue 1286](https://github.com/nothings/stb/issues/1286) and [GitHub Issue 1288](https://github.com/nothings/stb/issues/1288).