PT-2020-12807 · Sixel+2 · Libsixel+2

Sleicaspero

·

Published

2020-04-12

·

Updated

2024-12-20

·

CVE-2020-11721

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libsixel version 1.8.6
Description The issue is related to an uninitialized pointer in the load png function in loader.c in libsixel.a of libsixel, leading to an invalid call to free(), which can cause a denial of service.
Recommendations For libsixel version 1.8.6, consider updating to a newer version that contains a fix for this issue, as the current version has an uninitialized pointer that can lead to a denial of service.

Exploit

Fix

DoS

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1540
ALT-PU-2023-1591
ALT-PU-2024-17256
CVE-2020-11721

Affected Products

Alt Linux
Debian
Libsixel