CVE-2019-3574: High severity Libsixel Project Libsixel vulnerability
Published Jan 2, 2019
·Updated
In libsixel v1.8.2, there is a heap-based buffer over-read in the function loadjpeg() in the file loader.c, as demonstrated by img2sixel.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.2
saitoha libsixel=1.8.2
Event History
Jan 2, 2019
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-3574.
2
What is the severity of CVE-2019-3574?
The severity of CVE-2019-3574 is high with a CVSS score of 7.8.
3
What is the affected software?
The affected software is libsixel v1.8.2.
4
What is the CWE of CVE-2019-3574?
The CWE of CVE-2019-3574 is CWE-125.
5
How can I fix CVE-2019-3574?
There is currently no known fix for CVE-2019-3574. It is recommended to update to the latest version of libsixel when a fix becomes available.