CVE-2020-21548: Buffer Overflow
Published Sep 17, 2021
·Updated
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixelencodehighcolor function in tosixel.c.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.3
saitoha libsixel=1.8.3
Remediation
Patch Available
Event History
Sep 17, 2021
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-21548?
CVE-2020-21548 is a vulnerability in Libsixel 1.8.3 that allows a heap-based buffer overflow.
2
How severe is CVE-2020-21548?
CVE-2020-21548 has a severity rating of 8.8 (high).
3
What software is affected by CVE-2020-21548?
Libsixel 1.8.3 is affected by CVE-2020-21548.
4
What is the CWE of CVE-2020-21548?
CVE-2020-21548 belongs to CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-787 (Out-of-bounds Write).
5
How can I fix CVE-2020-21548?
Update Libsixel to a version that is not affected by CVE-2020-21548.