First published: Tue Sep 14 2021(Updated: )
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libsixel Project Libsixel | <1.8.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-21048.
The severity of CVE-2020-21048 is medium with a score of 6.5.
The affected software for CVE-2020-21048 is Libsixel version up to exclusive 1.8.4.
An attacker can exploit CVE-2020-21048 by using a crafted PNG file to cause a denial of service (DoS).
Yes, a fix is available for CVE-2020-21048 in version 1.8.4 of Libsixel.