CVE-2019-19777: High severity Libsixel Project Libsixel vulnerability
Published Dec 13, 2019
·Updated
stbimage.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbiloadmain.
Affected Software
3 affected components
Libsixel Project Libsixel=1.8.2
Nothings Stb Image.h=2.23
saitoha libsixel=1.8.2
Event History
Dec 13, 2019
CVE Published
via MITRE·01:05 AM
Data Sourced
via MITRE·01:05 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2019-19777.
2
What is the severity of CVE-2019-19777?
The severity of CVE-2019-19777 is high with a severity value of 8.8.
3
What is the affected software for CVE-2019-19777?
The affected software for CVE-2019-19777 includes libsixel version 1.8.2 and stb_image.h version 2.23.
4
What is the CWE ID for CVE-2019-19777?
The CWE ID for CVE-2019-19777 is 125.
5
Is there a reference for CVE-2019-19777?
Yes, there is a reference for CVE-2019-19777. You can find it at https://github.com/saitoha/libsixel/issues/109.