First published: Tue Jan 25 2022(Updated: )
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libsixel Project Libsixel | <=1.10.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-45340.
The severity of CVE-2021-45340 is medium with a severity value of 6.5.
Libsixel prior to and including v1.10.3 is affected by CVE-2021-45340.
CVE-2021-45340 can be exploited by attackers through a crafted PICT file, causing a denial of service (DOS) attack.
A fix for CVE-2021-45340 may be available in a later version of Libsixel, please refer to the official Libsixel project for updates.