CVE-2020-21048
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/09/2021
Last modified:
24/09/2021
Description
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:libsixel_project:libsixel:*:*:*:*:*:*:*:* | 1.8.4 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://bitbucket.org/netbsd/pkgsrc/commits/6f0c011cbfccdffa635d04c84433b1a02687adad
- https://github.com/saitoha/libsixel/blob/master/ChangeLog
- https://github.com/saitoha/libsixel/commit/cb373ab6614c910407c5e5a93ab935144e62b037
- https://github.com/saitoha/libsixel/issues/73
- https://github.com/saitoha/libsixel/releases/tag/v1.8.4



