CVE-2022-29978: Medium severity Libsixel Project Libsixel vulnerability
Published May 11, 2022
·Updated
There is a floating point exception error in sixelencoderdoresize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
Affected Software
2 affected components
Libsixel Project Libsixel=1.8.6
saitoha libsixel=1.8.6
Event History
May 11, 2022
CVE Published
via MITRE·01:12 PM
Data Sourced
via MITRE·01:12 PM
Description
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this flaw?
The vulnerability ID is CVE-2022-29978.
2
Where does the vulnerability occur?
The vulnerability occurs in the sixel_encoder_do_resize function in encoder.c at line 633 of libsixel img2sixel 1.8.6.
3
What is the severity level of CVE-2022-29978?
The severity level of CVE-2022-29978 is medium.
4
How can remote attackers exploit this vulnerability?
Remote attackers can leverage this vulnerability by using a crafted JPEG file to cause a denial-of-service.
5
Is there a fix available for this vulnerability?
At the time of writing, there is no publicly known fix available for CVE-2022-29978. It is recommended to follow the advisory provided by the vendor or the software developer for any updates or patches.