First published: Thu Mar 17 2022(Updated: )
** DISPUTED ** stb_truetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbtt__find_table at stb_truetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nothings stb true type | =1.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-25516.
The severity rating of CVE-2022-25516 is medium with a score of 6.5.
The affected software is stb_truetype.h version 1.26.
CVE-2022-25516 is a heap-buffer-overflow vulnerability in stb_truetype.h version 1.26.
At the moment, there are no known fixes or patches available for CVE-2022-25516. It is recommended to follow the updates from the vendor or project for any future developments.