CVE-2022-27046Use After Free in Project Libsixel

CWE-416Use After Free5 documents5 sources
Severity
8.8HIGHNVD
EPSS
0.3%
top 43.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 8
Latest updateApr 9

Description

libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
GHSA-h333-v9mv-m6g4: libsixel 12022-04-09
CVEList
CVE-2022-27046: libsixel 12022-04-08
OSV
CVE-2022-27046: libsixel 12022-04-08

📋Vendor Advisories

1
Debian
CVE-2022-27046: libsixel - libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/s...2022
CVE-2022-27046 — Use After Free in Project Libsixel | cvebase