CVE-2018-19759: Medium severity Libsixel Project Libsixel vulnerability
Published Nov 30, 2018
·Updated
There is a heap-based buffer over-read at stbimagewrite.h (function: stbiwritepngtomem) in libsixel 1.8.2 that will cause a denial of service.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.2
saitoha libsixel=1.8.2
Event History
Nov 30, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2018-19759?
CVE-2018-19759 is a vulnerability that leads to a heap-based buffer over-read in libsixel 1.8.2.
2
What is the severity of CVE-2018-19759?
The severity of CVE-2018-19759 is medium, with a CVSS score of 5.5.
3
What is the affected software for CVE-2018-19759?
The affected software for CVE-2018-19759 is libsixel 1.8.2.
4
How does CVE-2018-19759 cause a denial of service?
CVE-2018-19759 causes a denial of service due to a heap-based buffer over-read in stbi_write_png_to_mem function in libsixel 1.8.2.
5
How can I fix CVE-2018-19759?
To fix CVE-2018-19759, update to a version of libsixel that is not affected by the vulnerability.