CVE-2018-19756: Medium severity Libsixel Project Libsixel vulnerability
Published Nov 30, 2018
·Updated
There is a heap-based buffer over-read at stbimage.h (function: stbitgaload) in libsixel 1.8.2 that will cause a denial of service.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.2
saitoha libsixel=1.8.2
Event History
Nov 30, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-19756?
CVE-2018-19756 is a heap-based buffer over-read vulnerability in libsixel 1.8.2 that can result in a denial of service.
2
How does CVE-2018-19756 impact the affected software?
CVE-2018-19756 can cause a denial of service by triggering a heap-based buffer over-read in libsixel 1.8.2.
3
What is the severity of CVE-2018-19756?
CVE-2018-19756 has a severity rating of medium with a CVSS score of 5.5.
4
How can I fix CVE-2018-19756?
To fix CVE-2018-19756, update libsixel to version 1.8.3 or higher.
5
Where can I find more information about CVE-2018-19756?
You can find more information about CVE-2018-19756 at the following reference: https://bugzilla.redhat.com/show_bug.cgi?id=1649198