CVE Vulnerabilities

CVE-2021-42715

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Oct 21, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.2 MODERATE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

NameVendorStart VersionEnd Version
Stb_image.hNothings1.33 (including)2.27 (including)
LibstbUbuntufocal*
LibstbUbuntuhirsute*
LibstbUbuntuimpish*
LibstbUbuntukinetic*
LibstbUbuntulunar*
LibstbUbuntumantic*
LibstbUbuntuoracular*
LibstbUbuntuplucky*
LibstbUbuntutrusty*
LibstbUbuntuxenial*

References