CVE-2018-19763: Medium severity Libsixel Project Libsixel vulnerability
Published Nov 30, 2018
·Updated
There is a heap-based buffer over-read at writer.c (function: writepngtofile) in libsixel 1.8.2 that will cause a denial of service.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.2
saitoha libsixel=1.8.2
Event History
Nov 30, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-19763.
2
What is the title of this vulnerability?
The title of this vulnerability is 'There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2'.
3
What is the severity of CVE-2018-19763?
The severity of CVE-2018-19763 is medium, with a severity value of 5.5.
4
What software is affected by CVE-2018-19763?
The affected software is Libsixel version 1.8.2.
5
How can this vulnerability be exploited?
This vulnerability can be exploited through a heap-based buffer over-read at writer.c (function: write_png_to_file) in Libsixel 1.8.2, which can lead to a denial of service.