CVE-2019-19778: High severity Libsixel Project Libsixel vulnerability
Published Dec 13, 2019
·Updated
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function loadsixel at loader.c.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.2
saitoha libsixel=1.8.2
Event History
Dec 13, 2019
CVE Published
via MITRE·01:06 AM
Data Sourced
via MITRE·01:06 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-19778?
The severity of CVE-2019-19778 is high.
2
What is the affected software for CVE-2019-19778?
The affected software for CVE-2019-19778 is Libsixel version 1.8.2.
3
Is there a known fix for CVE-2019-19778?
Yes, there is a fix available for CVE-2019-19778. Please refer to the official Libsixel project for the fix.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2019-19778?
The Common Weakness Enumeration (CWE) ID for CVE-2019-19778 is CWE-125.
5
Where can I find more information about CVE-2019-19778?
More information about CVE-2019-19778 can be found at the following reference: [GitHub Issue](https://github.com/saitoha/libsixel/issues/110)