Skip to content

Commit

Permalink
NULL pointer dereference in stb_image (#1647)
Browse files Browse the repository at this point in the history
  • Loading branch information
mbrubeck authored Mar 19, 2023
1 parent 0888b44 commit 06a7d1f
Showing 1 changed file with 18 additions and 0 deletions.
18 changes: 18 additions & 0 deletions crates/stb_image/RUSTSEC-0000-0000.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
```toml
[advisory]
id = "RUSTSEC-0000-0000"
package = "stb_image"
date = "2023-03-19"
url = "https://github.com/servo/rust-stb-image/pull/102"
categories = ["memory-corruption"]
keywords = ["NULL-pointer-dereference"]

[versions]
patched = [">= 0.2.5"]
```

# NULL pointer derefernce in `stb_image`

A bug in error handling in the `stb_image` C library could cause a NULL pointer dereference when attempting to load an invalid or unsupported image file. This is fixed in version 0.2.5 and later of the `stb_image` Rust crate, by patching the C code to correctly handle NULL pointers.

Thank you to GitHub user 0xdd96 for finding and fixing this vulnerability.

0 comments on commit 06a7d1f

Please sign in to comment.