CVE-2022-27046: Use After Free
Published Apr 8, 2022
·Updated
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.6
saitoha libsixel=1.8.6
Event History
Apr 8, 2022
CVE Published
via MITRE·02:51 PM
Data Sourced
via MITRE·02:51 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-27046?
The severity of CVE-2022-27046 is high with a severity value of 8.8.
2
How does CVE-2022-27046 affect libsixel?
CVE-2022-27046 affects libsixel version 1.8.6.
3
What is the vulnerability type of CVE-2022-27046?
CVE-2022-27046 is a Heap Use After Free vulnerability.
4
How can the Heap Use After Free vulnerability in CVE-2022-27046 be exploited?
The Heap Use After Free vulnerability in CVE-2022-27046 can be exploited by manipulating memory after it has been freed.
5
Is there a fix available for CVE-2022-27046?
At the time of writing, there is no fix available for CVE-2022-27046. It is recommended to update to a version of libsixel that is not affected.