Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-45340

Опубликовано: 25 янв. 2022
Источник: debian
EPSS Низкий

Описание

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsixelfixed1.10.5-1package
libsixelignoredbookwormpackage
libsixelno-dsabullseyepackage
libsixelno-dsabusterpackage
libsixelno-dsastretchpackage
libstbunfixedpackage
libstbno-dsatrixiepackage
libstbno-dsabookwormpackage

Примечания

  • https://github.com/libsixel/libsixel/issues/51

  • Fixed by: https://github.com/libsixel/libsixel/pull/52

  • libsixel bundles libstb and has fixed this issue, but a patch in src:libstb is missing:

  • https://github.com/saitoha/libsixel/commit/1c58a6ea708b6fa793ffb5a10798ccfea36e8eed (v1.8.7)

EPSS

Процентиль: 38%
0.00163
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

CVSS3: 6.5
nvd
около 4 лет назад

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

github
около 4 лет назад

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

EPSS

Процентиль: 38%
0.00163
Низкий