CVE Vulnerabilities

CVE-2021-42715

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Oct 21, 2021 | Modified: Nov 07, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Stb_image.h Nothings 1.33 (including) 2.27 (including)
Libstb Ubuntu hirsute *
Libstb Ubuntu impish *
Libstb Ubuntu kinetic *
Libstb Ubuntu lunar *
Libstb Ubuntu mantic *
Libstb Ubuntu trusty *
Libstb Ubuntu xenial *

References