CVE-2021-37789 describes a heap-based buffer overflow vulnerability in stb_image.h version 2.27, specifically within the stbi__jpeg_load function, affecting Debian Linux and stb_project products. This vulnerability carries a high CVSS score of 8.1, indicating a network-based attack with low complexity that requires user interaction, potentially leading to information disclosure or denial of service. While no active exploitation, public exploits (Metasploit, Nuclei, ExploitDB), or significant community discussion have been observed, its high severity warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.27CPE matchmatch criteria | cpe:2.3:a:stb_project:stb:2.27:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.