VYPR
Medium severity6.5NVD Advisory· Published Oct 21, 2023· Updated Jun 17, 2026

CVE-2023-45662

CVE-2023-45662

Description

stb_image is a single file MIT licensed library for processing images. When stbi_set_flip_vertically_on_load is set to TRUE and req_comp is set to a number that doesn’t match the real number of components per pixel, the library attempts to flip the image vertically. A crafted image file can trigger memcpy out-of-bounds read because bytes_per_pixel used to calculate bytes_per_row doesn’t match the real image array dimensions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:nothings:stb_image.h:2.28:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:nothings:stb_image.h:2.28:*:*:*:*:*:*:*
    • (no CPE)
  • Range: <= 2.28

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.