CVE-2019-20140: Buffer Overflow
Published Dec 30, 2019
·Updated
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gifoutcode at fromgif.c.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.4
saitoha libsixel=1.8.4
Remediation
Patch Available
Event History
Dec 30, 2019
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2019-20140?
CVE-2019-20140 refers to a heap-based buffer overflow vulnerability in the function gif_out_code at fromgif.c in libsixel 1.8.4.
2
What software is affected by CVE-2019-20140?
The software affected by CVE-2019-20140 is libsixel 1.8.4 by the Libsixel Project.
3
What is the severity of CVE-2019-20140?
CVE-2019-20140 has a severity rating of high with a score of 8.8.
4
How does CVE-2019-20140 work?
CVE-2019-20140 is a heap-based buffer overflow vulnerability that can be exploited through the gif_out_code function in libsixel 1.8.4, allowing attackers to execute arbitrary code or cause a denial of service.
5
How can I fix the CVE-2019-20140 vulnerability?
To fix the CVE-2019-20140 vulnerability, it is recommended to update to a version of libsixel that is not affected by the issue.