CVE-2020-21677: Buffer Overflow
Published Aug 10, 2021
·Updated
A heap-based buffer overflow in the sixelencoderoutputwithoutmacro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.4
saitoha libsixel=1.8.4
Remediation
Patch Available
Event History
Aug 10, 2021
CVE Published
via MITRE·08:19 PM
Data Sourced
via MITRE·08:19 PM
Description
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this heap-based buffer overflow?
The vulnerability ID is CVE-2020-21677.
2
What is the title of this vulnerability?
The title of this vulnerability is 'A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4'.
3
What is the affected software?
The affected software is Libsixel 1.8.4.
4
What is the severity of this vulnerability?
The severity of this vulnerability is medium with a CVSS score of 6.5.
5
How can attackers exploit this vulnerability?
Attackers can exploit this vulnerability by converting a crafted PNG file into Sixel format.