CVE-2025-3409

NameCVE-2025-3409
DescriptionA vulnerability classified as critical has been found in Nothings stb up to f056911. This affects the function stb_include_string. The manipulation of the argument path_to_includes leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libstb (PTS)bullseye0.0~git20200713.b42009b+ds-1undetermined
bookworm0.0~git20220908.8b5f1f3+ds-1undetermined
sid, trixie0.0~git20241109.5c20573+ds-1undetermined

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libstbsource(unstable)undetermined

Notes

check upstream

Search for package or bug name: Reporting problems