CVE-2022-28042: Use After Free
stbimage.h v2.27 was discovered to contain an heap-based use-after-free via the function stbijpeghuffdecode.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in stb_image.h v2.27?
The vulnerability ID for this issue in stb_image.h v2.27 is CVE-2022-28042.
What is the description of the vulnerability?
The vulnerability in stb_image.h v2.27 is a heap-based use-after-free via the function stbi__jpeg_huff_decode.
Which software versions are affected by this vulnerability?
The software versions affected by this vulnerability are stb_image.h v2.27, Fedora 34, Fedora 35, Fedora 36, and Debian Debian Linux 10.0.
What is the severity of CVE-2022-28042?
The severity of CVE-2022-28042 is high (CVSS score: 8.8).
Are there any references related to this vulnerability?
Yes, there are references related to this vulnerability. They can be found at the following links: [Link 1](https://github.com/nothings/stb/issues/1289), [Link 2](https://github.com/nothings/stb/pull/1297), [Link 3](https://lists.debian.org/debian-lts-announce/2023/01/msg00045.html).