CVE-2019-11024: Medium severity Libsixel Project Libsixel vulnerability
Published Apr 8, 2019
·Updated
The loadpnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.2
saitoha libsixel=1.8.2
Event History
Apr 8, 2019
CVE Published
via MITRE·10:20 PM
Data Sourced
via MITRE·10:20 PM
Description
Data Sourced
via NVD·11:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-11024.
2
What is the severity rating of CVE-2019-11024?
CVE-2019-11024 has a severity rating of medium.
3
What is the affected software for CVE-2019-11024?
The affected software for CVE-2019-11024 is libsixel version 1.8.2.
4
What is the description of CVE-2019-11024?
CVE-2019-11024 is a vulnerability in libsixel 1.8.2 that causes infinite recursion in the load_pnm function in frompnm.c.
5
How can I fix CVE-2019-11024?
To fix CVE-2019-11024, update your libsixel installation to a version that is not affected by the vulnerability.