First published: Fri Nov 30 2018(Updated: )
There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libsixel Project Libsixel | =1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19756 is a heap-based buffer over-read vulnerability in libsixel 1.8.2 that can result in a denial of service.
CVE-2018-19756 can cause a denial of service by triggering a heap-based buffer over-read in libsixel 1.8.2.
CVE-2018-19756 has a severity rating of medium with a CVSS score of 5.5.
To fix CVE-2018-19756, update libsixel to version 1.8.3 or higher.
You can find more information about CVE-2018-19756 at the following reference: https://bugzilla.redhat.com/show_bug.cgi?id=1649198