CVE-2020-21048: Medium severity Libsixel Project Libsixel vulnerability
Published Sep 14, 2021
·Updated
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
Affected Software
2 affected components
Libsixel Project Libsixel<1.8.4
saitoha libsixel<1.8.4
Remediation
Patch Available
Event History
Sep 14, 2021
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-21048.
2
What is the severity of CVE-2020-21048?
The severity of CVE-2020-21048 is medium with a score of 6.5.
3
What is the affected software for CVE-2020-21048?
The affected software for CVE-2020-21048 is Libsixel version up to exclusive 1.8.4.
4
How can an attacker exploit CVE-2020-21048?
An attacker can exploit CVE-2020-21048 by using a crafted PNG file to cause a denial of service (DoS).
5
Is there any fix available for CVE-2020-21048?
Yes, a fix is available for CVE-2020-21048 in version 1.8.4 of Libsixel.