CVE-2023-43898

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
03/10/2023
Last modified:
17/06/2025

Description

Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pic file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nothings:stb_image.h:2.28:*:*:*:*:*:*:*