Oct. 21, 2023, 12:15 a.m. |

National Vulnerability Database web.nvd.nist.gov

stb_image is a single file MIT licensed library for processing images. It may look like `stbi__load_gif_main` doesn’t give guarantees about the content of output value `*delays` upon failure. Although it sets `*delays` to zero at the beginning, it doesn’t do it in case the image is not recognized as GIF and a call to `stbi__load_gif_main_outofmem` only frees possibly allocated memory in `*delays` without resetting it to zero. Thus it would be fair to say the caller of `stbi__load_gif_main` is responsible …

call case cve failure file gif image images library may mit single value

Malware Analyst - TASO / Active Secret

@ Peraton | Arlington, VA, United States

Information Security Engineer

@ Deel | Anywhere (APAC)

Cybersecurity Engineer

@ Booz Allen Hamilton | USA, DC, Washington (1125 15th St NW)

Director, Security Engineering

@ Warner Bros. Discovery | GA Atlanta 1050 Techwood Drive NW

Consultant Senior Securité Réseaux

@ Devoteam | Tunis, Tunisia

SOC Analyst, Mid

@ Peraton | Washington, DC, United States