5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
by @mweinelt Activity log
- Created automatic suggestion
- @mweinelt removed package raylib-games
- @mweinelt removed package ocamlPackages.raylib
- @mweinelt removed package haskellPackages.h-raylib
- @mweinelt removed package python312Packages.raylib-python-cffi
- @mweinelt removed package python313Packages.raylib-python-cffi
- @mweinelt removed maintainer @Sigmanificient
- @mweinelt added maintainer @ehmry
- @mweinelt removed maintainer @ehmry
- @mweinelt accepted
- @mweinelt published on GitHub
raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow
A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageFontAtlas of the file src/rtext.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. This patch is called 5a3391fdce046bc5473e52afbd835dd2dc127146. Applying a patch is advised to resolve this issue.
References
-
VDB-341705 | raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow vdb-entrytechnical-description
-
-
Submit #733341 | raysan5 raylib 909f040 Heap-based Buffer Overflow third-party-advisory
-
Submit #733342 | raysan5 raylib 909f040 Heap-based Buffer Overflow (Duplicate) third-party-advisory
-
https://github.com/raysan5/raylib/issues/5433 issue-tracking
-
https://github.com/raysan5/raylib/pull/5450 issue-tracking
-
VDB-341705 | raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow vdb-entrytechnical-description
-
-
Submit #733341 | raysan5 raylib 909f040 Heap-based Buffer Overflow third-party-advisory
-
Submit #733342 | raysan5 raylib 909f040 Heap-based Buffer Overflow (Duplicate) third-party-advisory
-
https://github.com/raysan5/raylib/issues/5433 issue-tracking
-
https://github.com/raysan5/raylib/pull/5450 issue-tracking
Affected products
- ==909f040
Package maintainers
-
@diniamo diniamo <diniamo53@gmail.com>