First published: Sun Dec 08 2019(Updated: )
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libsixel Project Libsixel | =1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-19635.
The severity of CVE-2019-19635 is critical with a score of 9.8.
The affected software for CVE-2019-19635 is libsixel version 1.8.2.
The CWE ID for CVE-2019-19635 is CWE-119 and CWE-787.
To fix CVE-2019-19635, update to a version of libsixel that is not affected by the vulnerability.