CVE-2020-21049: Medium severity Libsixel Project Libsixel vulnerability
Published Sep 14, 2021
·Updated
An invalid read in the stbimage.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
Affected Software
2 affected components
Libsixel Project Libsixel<1.8.5
saitoha libsixel<1.8.5
Remediation
Patch Available
Event History
Sep 14, 2021
CVE Published
via MITRE·03:09 PM
Data Sourced
via MITRE·03:09 PM
Description
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-21049.
2
What is the severity of CVE-2020-21049?
The severity of CVE-2020-21049 is medium with a CVSS score of 6.5.
3
How can attackers exploit CVE-2020-21049?
Attackers can exploit CVE-2020-21049 by causing a denial of service (DOS) via a crafted PSD file.
4
What is the affected software for CVE-2020-21049?
The affected software for CVE-2020-21049 is libsixel prior to v1.8.5.
5
Is there a fix available for CVE-2020-21049?
Yes, the fix for CVE-2020-21049 is available in libsixel version 1.8.5.