Medium severity5.5NVD Advisory· Published Oct 3, 2023· Updated Jun 17, 2026
CVE-2023-43898
CVE-2023-43898
Description
Nothings stb 2.28 was discovered to contain a Null Pointer Dereference via the function stbi__convert_format. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted pic file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:nothings:stb_image.h:2.28:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2- github.com/nothings/stb/pull/1454nvdIssue TrackingPatch
- github.com/nothings/stb/issues/1452nvdExploitIssue TrackingPatchThird Party Advisory
News mentions
0No linked articles in our index yet.