CVE-2021-45340: Null Pointer Dereference
Published Jan 25, 2022
·Updated
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stbimage.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
Affected Software
2 affected components
Libsixel Project Libsixel<=1.10.3
Libsixel libsixel<=1.10.3
Remediation
Patch Available
Event History
Jan 25, 2022
CVE Published
via MITRE·11:36 AM
Data Sourced
via MITRE·11:36 AM
Description
Data Sourced
via NVD·12:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-45340.
2
What is the severity of CVE-2021-45340?
The severity of CVE-2021-45340 is medium with a severity value of 6.5.
3
What is affected by CVE-2021-45340?
Libsixel prior to and including v1.10.3 is affected by CVE-2021-45340.
4
How can CVE-2021-45340 be exploited?
CVE-2021-45340 can be exploited by attackers through a crafted PICT file, causing a denial of service (DOS) attack.
5
Is there a fix available for CVE-2021-45340?
A fix for CVE-2021-45340 may be available in a later version of Libsixel, please refer to the official Libsixel project for updates.