Debian Libsixel vulnerabilities
40 known vulnerabilities affecting debian/libsixel.
Total CVEs
40
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM14LOW19
Vulnerabilities
Page 1 of 2
CVE-2025-9300P3MEDIUMCVSS 4.8fixed in libsixel 1:1.8.7-1 (forky)2025
CVE-2025-9300 [MEDIUM] CVE-2025-9300: libsixel - A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this iss...
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is identified as
debian
CVE-2019-19636P3LOWCVSS 9.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19636 [CRITICAL] CVE-2019-19636: libsixel - An issue was discovered in libsixel 1.8.2. There is an integer overflow in the f...
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_encode_body at tosixel.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-19637P3LOWCVSS 9.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19637 [CRITICAL] CVE-2019-19637: libsixel - An issue was discovered in libsixel 1.8.2. There is an integer overflow in the f...
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2022-27044P3HIGHCVSS 8.8fixed in libsixel 1.10.3-1 (bookworm)2022
CVE-2022-27044 [HIGH] CVE-2022-27044: libsixel - libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: open
forky: resolved (fixed in 1.10.3-1)
sid: resolved (fixed in 1.10.3-1)
trixie: resolved (fixed in 1.10.3-1)
debian
CVE-2019-19638P3LOWCVSS 9.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19638 [CRITICAL] CVE-2019-19638: libsixel - An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow...
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2021-41715P3HIGHCVSS 8.8fixed in libsixel 1.10.3-1 (bookworm)2021
CVE-2021-41715 [HIGH] CVE-2021-41715: libsixel - libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: open
forky: resolved (fixed in 1.10.3-1)
sid: resolved (fixed in 1.10.3-1)
trixie: resolved (fixed in 1.10.3-1)
debian
CVE-2019-19635P3LOWCVSS 9.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19635 [CRITICAL] CVE-2019-19635: libsixel - An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow...
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2020-21548P3HIGHCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2020
CVE-2020-21548 [HIGH] CVE-2020-21548: libsixel - Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcol...
Libsixel 1.8.3 contains a heap-based buffer overflow in the sixel_encode_highcolor function in tosixel.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2020-21547P3HIGHCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2020
CVE-2020-21547 [HIGH] CVE-2020-21547: libsixel - Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs funct...
Libsixel 1.8.2 contains a heap-based buffer overflow in the dither_func_fs function in tosixel.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2021-40656P3HIGHCVSS 8.8fixed in libsixel 1.10.3-1 (bookworm)2021
CVE-2021-40656 [HIGH] CVE-2021-40656: libsixel - libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:86...
libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: open
forky: resolved (fixed in 1.10.3-1)
sid: resolved (fixed in 1.10.3-1)
trixie: resolved (fixed in 1.10.3-1)
debian
CVE-2019-19777P3LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19777 [HIGH] CVE-2019-19777: libsixel - stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other produ...
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2022-27046P3HIGHCVSS 8.8fixed in libsixel 1.10.3-1 (bookworm)2022
CVE-2022-27046 [HIGH] CVE-2022-27046: libsixel - libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/s...
libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: open
forky: resolved (fixed in 1.10.3-1)
sid: resolved (fixed in 1.10.3-1)
trixie: resolved (fixed in 1.10.3-1)
debian
CVE-2019-20205P3LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20205 [HIGH] CVE-2019-20205: libsixel - libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-20140P4LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20140 [HIGH] CVE-2019-20140: libsixel - An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow...
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-20094P4LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20094 [HIGH] CVE-2019-20094: libsixel - An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow...
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-19778P4LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19778 [HIGH] CVE-2019-19778: libsixel - An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-rea...
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-3574P4LOWCVSS 7.8fixed in libsixel 1.8.2-2 (bookworm)2019
CVE-2019-3574 [HIGH] CVE-2019-3574: libsixel - In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_...
In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2018-19762P4HIGHCVSS 7.8fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19762 [HIGH] CVE-2018-19762: libsixel - There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_res...
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of service or possibly unspecified other impact.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-
debian
CVE-2020-21050P4MEDIUMCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2020
CVE-2020-21050 [MEDIUM] CVE-2020-21050: libsixel - Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_pr...
Libsixel prior to v1.8.3 contains a stack buffer overflow in the function gif_process_raster at fromgif.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2018-14073P4LOWCVSS 7.5fixed in libsixel 1.8.2-1 (bookworm)2018
CVE-2018-14073 [HIGH] CVE-2018-14073: libsixel - libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c.
libsixel 1.8.1 has a memory leak in sixel_allocator_new in allocator.c.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resolved (fixed in 1.8.2-1)
sid: resolved (fixed in 1.8.2-1)
trixie: resolved (fixed in 1.8.2-1)
debian
1 / 2Next →