CVE-2022-27938: Medium severity Libsixel Project Libsixel vulnerability
Published Mar 26, 2022
·Updated
stbimage.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbicreatepngimageraw.
Affected Software
3 affected components
Libsixel Project Libsixel=2.19
Libsixel libsixel<1.10.4
saitoha libsixel<1.8.7
Remediation
Patch Available
Event History
Mar 26, 2022
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
Description
Data Sourced
via NVD·01:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-27938?
CVE-2022-27938 is a vulnerability in stb_image.h library version 2.19, used in libsixel and other products, which allows an attacker to reach an assertion in stbi__create_png_image_raw.
2
How severe is CVE-2022-27938?
CVE-2022-27938 has a severity rating of 5.5, which is classified as medium.
3
Which software is affected by CVE-2022-27938?
The software affected by CVE-2022-27938 is Libsixel version 2.19.
4
How can I fix CVE-2022-27938?
To fix CVE-2022-27938, update Libsixel to a version that is not affected by the vulnerability.
5
Where can I find more information about CVE-2022-27938?
You can find more information about CVE-2022-27938 at the following link: [GitHub Issue #163](https://github.com/saitoha/libsixel/issues/163)