Security Advisory

CVE-2023-45661

6.5
MEDIUM

Vulnerability Description

stb_image is a single file MIT licensed library for processing images. A crafted image file may trigger out of bounds memcpy read in `stbi__gif_load_next`. This happens because two_back points to a memory address lower than the start of the buffer out. This issue may be used to leak internal memory allocation information.
Published Date October 21, 2023
Official Source NIST NVD Advisory