First published: Thu Mar 17 2022(Updated: )
** DISPUTED ** stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function ttULONG() at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nothings stb true type | =1.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25515 is a heap buffer overflow vulnerability in stb_truetype.h v1.26.
The severity of CVE-2022-25515 is medium with a CVSS score of 6.5.
CVE-2022-25515 affects stb_truetype.h v1.26.
At the moment, there are no official patches or fixes available for CVE-2022-25515. It is recommended to follow the latest updates and mitigation strategies provided by the vendor or software developer.
You can find more information about CVE-2022-25515 at the following references: [GitHub Issue 1286](https://github.com/nothings/stb/issues/1286) and [GitHub Issue 1288](https://github.com/nothings/stb/issues/1288).