First published: Wed Jan 02 2019(Updated: )
In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libsixel Project Libsixel | =1.8.2 | |
=1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-3574.
The severity of CVE-2019-3574 is high with a CVSS score of 7.8.
The affected software is libsixel v1.8.2.
The CWE of CVE-2019-3574 is CWE-125.
There is currently no known fix for CVE-2019-3574. It is recommended to update to the latest version of libsixel when a fix becomes available.