Single-file public domain libraries for C/C++.
Security Fix(es):
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds write in f->vendor[len] = (char)'\0';. The root cause is that if the len read in start_decoder is -1 and len + 1 becomes 0 when passed to setup_malloc. The setup_malloc behaves differently when f->alloc.alloc_buffer is pre-allocated. Instead of returning NULL as in malloc case it shifts the pre-allocated buffer by zero and returns the currently available memory block. This issue may lead to code execution.(CVE-2023-45675)
{
"severity": "High"
}{
"aarch64": [
"stb_image_write-devel-1.16.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_ds-devel-0.67.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb-devel-0.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_image-devel-2.27.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_image_resize-devel-0.97.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_truetype-devel-1.26.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_tilemap_editor-devel-0.42.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_perlin-devel-0.5.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_rect_pack-devel-1.1.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_voxel_render-devel-0.89.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_vorbis-devel-1.22.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_dxt-devel-1.12.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_hexwave-devel-0.5.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_divide-devel-0.94.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_connected_components-devel-0.96.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_herringbone_wang_tile-devel-0.7.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_sprintf-devel-1.10.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_textedit-devel-1.14.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_c_lexer-devel-0.12.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_easy_font-devel-1.1.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm",
"stb_leakcheck-devel-0.6.20220908git8b5f1f3-0.13.oe2203sp3.aarch64.rpm"
],
"noarch": [
"stb-help-0.20220908git8b5f1f3-0.13.oe2203sp3.noarch.rpm"
],
"x86_64": [
"stb_vorbis-devel-1.22.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_divide-devel-0.94.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_dxt-devel-1.12.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_tilemap_editor-devel-0.42.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_easy_font-devel-1.1.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_perlin-devel-0.5.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_hexwave-devel-0.5.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_sprintf-devel-1.10.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_image_resize-devel-0.97.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_herringbone_wang_tile-devel-0.7.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_image_write-devel-1.16.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_c_lexer-devel-0.12.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_image-devel-2.27.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_rect_pack-devel-1.1.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_truetype-devel-1.26.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_textedit-devel-1.14.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_connected_components-devel-0.96.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_leakcheck-devel-0.6.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb-devel-0.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_voxel_render-devel-0.89.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm",
"stb_ds-devel-0.67.20220908git8b5f1f3-0.13.oe2203sp3.x86_64.rpm"
],
"src": [
"stb-0.20220908git8b5f1f3-0.13.oe2203sp3.src.rpm"
]
}