CVE-2023-45677: GHSL-2023-145_GHSL-2023-151/GHSL-2023-165_GHSL-2023-172: Several memory access violations in stb_image and stb_vorbis
stbimage.h and stbvorbis libraries contain several memory access violations of different severity.
Other sources
stbvorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in f->vendor[len] = (char)'\0';. The root cause is that if len read in startdecoder is a negative number and setupmalloc successfully allocates memory in that case, but memory write is done with a negative index len. Similarly if len is INTMAX the integer overflow len+1 happens in f->vendor = (char)setupmalloc(f, sizeof(char) (len+1)); and f->commentlist[i] = (char)setupmalloc(f, sizeof(char) (len+1));. This issue may lead to code execution.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45677?
CVE-2023-45677 is a vulnerability in stb_vorbis library that allows for a heap buffer out of bounds write in start_decoder function.
What is the severity of CVE-2023-45677?
The severity of CVE-2023-45677 is high with a CVSS score of 7.3.
How does CVE-2023-45677 affect the stb_vorbis library?
CVE-2023-45677 affects the stb_vorbis library version 1.22.
How can I fix the CVE-2023-45677 vulnerability?
To fix the CVE-2023-45677 vulnerability, it is recommended to update to the latest version of the stb_vorbis library.
Where can I find more information about CVE-2023-45677?
More information about CVE-2023-45677 can be found in the following references: [link1], [link2], [link3].