{"id":"GHSA-ppjr-267j-5p9x","aliases":["RUSTSEC-2023-0021"],"url":"https://o3.security/vulnerability/GHSA-ppjr-267j-5p9x","summary":"NULL pointer derefernce in `stb_image`","details":"A bug in error handling in the `stb_image` C library could cause a NULL pointer dereference when attempting to load an invalid or unsupported image file.  This is fixed in version 0.2.5 and later of the `stb_image` Rust crate, by patching the C code to correctly handle NULL pointers.\n","published":"2023-03-20T21:11:58Z","modified":"2023-11-08T04:21:46.866404Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"stb_image","fixedVersion":"0.2.5"}],"fix":{"url":"https://github.com/servo/rust-stb-image/pull/102","label":"servo/rust-stb-image#102"},"references":[{"type":"WEB","url":"https://github.com/servo/rust-stb-image/pull/102"},{"type":"PACKAGE","url":"https://github.com/servo/rust-stb-imag"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2023-0021.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T04:21:46.866404Z"}}