Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-20056

Опубликовано: 29 дек. 2019
Источник: debian

Описание

stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsixelfixed1.8.6-1package
libsixelno-dsabusterpackage
libsixelno-dsastretchpackage
libsixelno-dsajessiepackage
libstbfixed0.0~git20220908.8b5f1f3+ds-1package
libstbno-dsabullseyepackage
libstbno-dsabusterpackage

Примечания

  • libsixel PR: https://github.com/saitoha/libsixel/issues/126

  • libsixel patch: https://github.com/saitoha/libsixel/commit/814f831555ea2492d442e784ab5d594f6a8e2e8d

  • libstb PR: https://github.com/nothings/stb/issues/886

  • libstb patch: https://github.com/nothings/stb/commit/bfaccab17a648b315543d366c63aee575a0756b7

  • Fix might cause a regression:

  • https://github.com/nothings/stb/pull/960#pullrequestreview-615017993

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.

CVSS3: 6.5
nvd
около 6 лет назад

stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.

github
больше 3 лет назад

stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.

CVSS3: 6.5
fstec
около 6 лет назад

Уязвимость компонента stb_image.h реализации кодировщика/декодера SIXEL Libsixel библиотеки для C/C++ Libstb, позволяющая нарушителю вызвать отказ в обслуживании