CVE-2019-19635: Buffer Overflow
Published Dec 8, 2019
·Updated
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixeldecoderawimpl at fromsixel.c.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.2
saitoha libsixel=1.8.2
Event History
Dec 8, 2019
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-19635.
2
What is the severity of CVE-2019-19635?
The severity of CVE-2019-19635 is critical with a score of 9.8.
3
What is the affected software for CVE-2019-19635?
The affected software for CVE-2019-19635 is libsixel version 1.8.2.
4
What is the CWE ID for CVE-2019-19635?
The CWE ID for CVE-2019-19635 is CWE-119 and CWE-787.
5
How can I fix CVE-2019-19635?
To fix CVE-2019-19635, update to a version of libsixel that is not affected by the vulnerability.