ALT-PU-2020-2902-1
Closed vulnerabilities
BDU:2022-01680
Уязвимость компонента stb_image.h реализации кодировщика/декодера SIXEL Libsixel, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-01744
Уязвимость функции dither_func_fs компонента tosixel.c реализации кодировщика/декодера SIXEL Libsixel, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2022-02074
Уязвимость компонента dither.c реализации кодировщика/декодера SIXEL Libsixel, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-02076
Уязвимость функции gif_process_raster компонента fromgif.c реализации кодировщика/декодера SIXEL Libsixel, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2018-19756
There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service.
Modified: 2024-11-21
CVE-2018-19757
There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.
Modified: 2024-11-21
CVE-2018-19759
There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.
Modified: 2024-11-21
CVE-2018-19761
There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.
Modified: 2024-11-21
CVE-2018-19762
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of service or possibly unspecified other impact.
Modified: 2024-11-21
CVE-2018-19763
There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of service.
Modified: 2024-11-21
CVE-2019-11024
The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
Modified: 2024-11-21
CVE-2019-19635
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.
Modified: 2024-11-21
CVE-2019-19636
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.
Modified: 2024-11-21
CVE-2019-19637
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.
Modified: 2024-11-21
CVE-2019-19638
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.
Modified: 2024-11-21
CVE-2019-19777
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
Modified: 2024-11-21
CVE-2019-19778
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
Modified: 2024-11-21
CVE-2019-20022
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
Modified: 2024-11-21
CVE-2019-20023
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
Modified: 2024-11-21
CVE-2019-20024
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
Modified: 2024-11-21
CVE-2019-3573
In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.
Modified: 2024-11-21
CVE-2019-3574
In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.
Modified: 2024-11-21
CVE-2020-21048
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
- https://bitbucket.org/netbsd/pkgsrc/commits/6f0c011cbfccdffa635d04c84433b1a02687adad
- https://bitbucket.org/netbsd/pkgsrc/commits/6f0c011cbfccdffa635d04c84433b1a02687adad
- https://github.com/saitoha/libsixel/blob/master/ChangeLog
- https://github.com/saitoha/libsixel/blob/master/ChangeLog
- https://github.com/saitoha/libsixel/commit/cb373ab6614c910407c5e5a93ab935144e62b037
- https://github.com/saitoha/libsixel/commit/cb373ab6614c910407c5e5a93ab935144e62b037
- https://github.com/saitoha/libsixel/issues/73
- https://github.com/saitoha/libsixel/issues/73
- https://github.com/saitoha/libsixel/releases/tag/v1.8.4
- https://github.com/saitoha/libsixel/releases/tag/v1.8.4
Modified: 2024-11-21
CVE-2020-21049
An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
- https://bitbucket.org/netbsd/pkgsrc/commits/970a81d31ec7498e04d09b6b7771cef35f63cd28
- https://bitbucket.org/netbsd/pkgsrc/commits/970a81d31ec7498e04d09b6b7771cef35f63cd28
- https://github.com/saitoha/libsixel/blob/master/ChangeLog
- https://github.com/saitoha/libsixel/blob/master/ChangeLog
- https://github.com/saitoha/libsixel/commit/0b1e0b3f7b44233f84e5c9f512f8c90d6bbbe33d
- https://github.com/saitoha/libsixel/commit/0b1e0b3f7b44233f84e5c9f512f8c90d6bbbe33d
- https://github.com/saitoha/libsixel/issues/74
- https://github.com/saitoha/libsixel/issues/74
- https://github.com/saitoha/libsixel/releases/tag/v1.8.5
- https://github.com/saitoha/libsixel/releases/tag/v1.8.5
Modified: 2024-11-21
CVE-2020-21050
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
- https://bitbucket.org/netbsd/pkgsrc/commits/a27113e21179cbfbfae0c35f6a9edd6aa498faae
- https://bitbucket.org/netbsd/pkgsrc/commits/a27113e21179cbfbfae0c35f6a9edd6aa498faae
- https://cwe.mitre.org/data/definitions/121.html
- https://cwe.mitre.org/data/definitions/121.html
- https://github.com/saitoha/libsixel/blob/master/ChangeLog
- https://github.com/saitoha/libsixel/blob/master/ChangeLog
- https://github.com/saitoha/libsixel/commit/7808a06b88c11dbc502318cdd51fa374f8cd47ee
- https://github.com/saitoha/libsixel/commit/7808a06b88c11dbc502318cdd51fa374f8cd47ee
- https://github.com/saitoha/libsixel/issues/75
- https://github.com/saitoha/libsixel/issues/75
- https://github.com/saitoha/libsixel/releases/tag/v1.8.5
- https://github.com/saitoha/libsixel/releases/tag/v1.8.5
Modified: 2024-11-21
CVE-2020-21547
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.