CVE-2022-25516: Medium severity nothings stb true type vulnerability
Published Mar 17, 2022
·Updated
DISPUTED stbtruetype.h v1.26 was discovered to contain a heap-buffer-overflow via the function stbttfindtable at stbtruetype.h. NOTE: Third party has disputed stating that the source code has also a disclaimer that it should only be used with trusted input.
Affected Software
1 affected component
Nothings Stb Truetype.h=1.26
Event History
Mar 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Disputed
01:15 AM
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2022-25516.
2
What is the severity rating of CVE-2022-25516?
The severity rating of CVE-2022-25516 is medium with a score of 6.5.
3
What software is affected by CVE-2022-25516?
The affected software is stb_truetype.h version 1.26.
4
What is the description of CVE-2022-25516?
CVE-2022-25516 is a heap-buffer-overflow vulnerability in stb_truetype.h version 1.26.
5
Are there any fixes or patches available for CVE-2022-25516?
At the moment, there are no known fixes or patches available for CVE-2022-25516. It is recommended to follow the updates from the vendor or project for any future developments.