5.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV):
- Attack complexity (AC):
- Privileges required (PR):
- User interaction (UI):
- Scope (S):
- Confidentiality impact (C):
- Integrity impact (I):
- Availability impact (A):
raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow
A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageFontAtlas of the file src/rtext.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. This patch is called 5a3391fdce046bc5473e52afbd835dd2dc127146. Applying a patch is advised to resolve this issue.
References
-
VDB-341705 | raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow vdb-entrytechnical-description
-
-
Submit #733341 | raysan5 raylib 909f040 Heap-based Buffer Overflow third-party-advisory
-
Submit #733342 | raysan5 raylib 909f040 Heap-based Buffer Overflow (Duplicate) third-party-advisory
-
https://github.com/raysan5/raylib/issues/5433 issue-tracking
-
https://github.com/raysan5/raylib/pull/5450 issue-tracking
Affected products
- ==909f040
Matching in nixpkgs
pkgs.raylib
Simple and easy-to-use library to enjoy videogames programming
pkgs.raylib-games
Collection of games made with raylib
-
nixos-unstable 2022-10-24
- nixpkgs-unstable 2022-10-24
- nixos-unstable-small 2022-10-24
-
nixos-25.11 2022-10-24
- nixpkgs-25.11-darwin 2022-10-24
pkgs.ocamlPackages.raylib
OCaml bindings for Raylib (5.0.0)
pkgs.haskellPackages.h-raylib
Raylib bindings for Haskell
pkgs.python312Packages.raylib-python-cffi
Python CFFI bindings for Raylib
Package maintainers
-
@Sigmanificient Yohann Boniface <sigmanificient@gmail.com>
-
@Prince213 Sizhe Zhao <prc.zhao@outlook.com>
-
@wegank Weijia Wang <contact@weijia.wang>
-
@fricklerhandwerk Valentin Gagarin <valentin@fricklerhandwerk.de>
-
@ethancedwards8 Ethan Carter Edwards <ethan@ethancedwards.com>
-
@eljamm Fedi Jamoussi <fedi.jamoussi@protonmail.ch>
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>
-
@diniamo diniamo <diniamo53@gmail.com>
-
@ehmry Emery Hemingway <ehmry@posteo.net>
-
@r17x Rin <hi@rin.rocks>