{"id":"GHSA-3w9w-9833-gcpv","summary":"Security bug in ConvertToSinglePlane when used with untrusted content from the DDS loader","details":"### Impact\nA memory overwrite bug was reported by a security researcher in the **ConvertToSinglePlane** method via the *texconv* command-line tool when given an invalid height for planar video textures such as NV12. This can be a potential security bug for any clients of the library who follow the same pattern.\n\nThis issue *does not* impact use of the DDS texture loader itself, only when combined with `ConvertToSinglePlane` for converting multi-planar video formats. All other functions in the library fail immediately if given images in planar formats.\n\n### Patches\nThe fix to the specific area as well as general hardening can be found in [this PR](https://github.com/microsoft/DirectXTex/pull/307) and will be included in the This bug has been fixed in the January 31, 2023 or later release of DirectXTex.\n\n### Workarounds\nIf your code makes use of **ConvertToSinglePlane**, you can validate that the width & height alignment requirements are met for the input image before calling the function.\n","modified":"2024-12-04T05:41:30.914332Z","published":"2023-01-26T19:52:50Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-01-26T19:52:50Z","nvd_published_at":null,"cwe_ids":[]},"references":[{"type":"WEB","url":"https://github.com/microsoft/DirectXTex/security/advisories/GHSA-3w9w-9833-gcpv"},{"type":"WEB","url":"https://github.com/microsoft/DirectXTex/pull/307"},{"type":"PACKAGE","url":"https://github.com/microsoft/DirectXTex"}],"affected":[{"package":{"name":"directxtex_desktop_2019","ecosystem":"NuGet","purl":"pkg:nuget/directxtex_desktop_2019"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2023.1.31.1"}]}],"versions":["2022.10.18.1","2022.12.18.1","2022.5.10.1","2022.7.30.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-3w9w-9833-gcpv/GHSA-3w9w-9833-gcpv.json"}},{"package":{"name":"directxtex_desktop_win10","ecosystem":"NuGet","purl":"pkg:nuget/directxtex_desktop_win10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2023.1.31.1"}]}],"versions":["2018.11.20.1","2019.10.17.1","2019.12.17.1","2019.2.7.1","2019.4.26.1","2019.5.31.1","2019.8.23.1","2020.11.12.1","2020.2.15.1","2020.5.11.1","2020.6.15.1","2020.6.2.1","2020.7.2.1","2020.8.15.1","2020.9.30.1","2021.1.10.2","2021.11.8.1","2021.4.7.2","2021.6.10.1","2021.8.2.1","2022.10.18.1","2022.12.18.1","2022.3.1.1","2022.3.24.1","2022.5.10.1","2022.7.30.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-3w9w-9833-gcpv/GHSA-3w9w-9833-gcpv.json"}},{"package":{"name":"directxtex_uwp","ecosystem":"NuGet","purl":"pkg:nuget/directxtex_uwp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2023.1.31.1"}]}],"versions":["2017.11.1.1","2017.12.13.1","2018.10.26.1","2018.11.20.1","2018.2.9.1","2018.4.23.1","2018.5.11.1","2018.6.1.2","2018.7.4.1","2018.8.18.2","2018.8.5.1","2019.10.17.1","2019.12.17.1","2019.2.7.1","2019.4.26.1","2019.5.31.1","2019.8.23.1","2020.11.12.1","2020.2.15.1","2020.5.11.1","2020.6.15.1","2020.6.2.1","2020.7.2.1","2020.8.15.1","2020.9.30.1","2021.1.10.2","2021.11.8.1","2021.4.7.2","2021.6.10.1","2021.8.2.1","2022.10.18.1","2022.12.18.1","2022.3.1.1","2022.3.24.1","2022.5.10.1","2022.7.30.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/01/GHSA-3w9w-9833-gcpv/GHSA-3w9w-9833-gcpv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L"}]}