CVE-2025-9300: saitoha libsixel img2sixel encoder.c sixel_debug_print_palette stack-based overflow
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixeldebugprintpalette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is identified as 316c086e79d66b62c0c4bc66229ee894e4fdb7d1. Applying a patch is advised to resolve this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9300?
CVE-2025-9300 has a high severity due to its potential for stack-based buffer overflow exploitation.
How do I fix CVE-2025-9300?
To fix CVE-2025-9300, upgrade saitoha libsixel to version 1.10.4 or later, where the vulnerability has been addressed.
What are the impacts of CVE-2025-9300?
The impact of CVE-2025-9300 includes the possibility of remote code execution if a local attacker exploits the stack-based buffer overflow.
Who is affected by CVE-2025-9300?
CVE-2025-9300 affects all users of saitoha libsixel up to version 1.10.3.
Is CVE-2025-9300 exploitable remotely?
CVE-2025-9300 requires local access for exploitation, making it less of a concern for remote threats.