Vulnerabilities > CVE-2023-43898 - NULL Pointer Dereference vulnerability in Nothings STB Image.H 2.28

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
local
low complexity
nothings
CWE-476

Summary

Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pic file.

Vulnerable Configurations

Part Description Count
Application
Nothings
1

Common Weakness Enumeration (CWE)