Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-45340

Опубликовано: 25 янв. 2022
Источник: debian

Описание

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libsixelfixed1.10.5-1package
libsixelignoredbookwormpackage
libsixelno-dsabullseyepackage
libsixelno-dsabusterpackage
libsixelno-dsastretchpackage
libstbunfixedpackage
libstbno-dsatrixiepackage
libstbno-dsabookwormpackage

Примечания

  • https://github.com/libsixel/libsixel/issues/51

  • Fixed by: https://github.com/libsixel/libsixel/pull/52

  • libsixel bundles libstb and has fixed this issue, but a patch in src:libstb is missing:

  • https://github.com/saitoha/libsixel/commit/1c58a6ea708b6fa793ffb5a10798ccfea36e8eed (v1.8.7)

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 4 лет назад

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

CVSS3: 6.5
nvd
больше 4 лет назад

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

CVSS3: 6.5
github
больше 4 лет назад

In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.

CVSS3: 6.5
fstec
больше 4 лет назад

Уязвимость компонента stb_image.h библиотек для C/C++ Libstb, реализации кодировщика/декодера SIXEL Libsixel, позволяющая нарушителю вызвать отказ в обслуживании