CVE-2023-45667

CVE-2023-45667

stb_image is a single file MIT licensed library for processing images.

If `stbi__load_gif_main` in `stbi_load_gif_from_memory` fails it returns a null pointer and may keep the `z` variable uninitialized. In case the caller also sets the flip vertically flag, it continues and calls `stbi__vertical_flip_slices` with the null pointer result value and the uninitialized `z` value. This may result in a program crash.

Source: CVE-2023-45667

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다