Debian Libsixel vulnerabilities
40 known vulnerabilities affecting debian/libsixel.
Total CVEs
40
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM14LOW19
Vulnerabilities
Page 2 of 2
CVE-2018-14072P4LOWCVSS 7.5fixed in libsixel 1.8.2-1 (bookworm)2018
CVE-2018-14072 [HIGH] CVE-2018-14072: libsixel - libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buf...
libsixel 1.8.1 has a memory leak in sixel_decoder_decode in decoder.c, image_buffer_resize in fromsixel.c, and sixel_decode_raw in fromsixel.c.
Scope: local
bookworm: resolved (fixed in 1.8.2-1)
bullseye: resolved (fixed in 1.8.2-1)
forky: resolved (fixed in 1.8.2-1)
sid: resolved (fixed in 1.8.2-1)
trixie: resolved (fixed in 1.8.2-1)
debian
CVE-2020-19668P4MEDIUMCVSS 6.5fixed in libsixel 1.10.3-1 (bookworm)2020
CVE-2020-19668 [MEDIUM] CVE-2020-19668: libsixel - Unverified indexs into the array lead to out of bound access in the gif_out_code...
Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: open
forky: resolved (fixed in 1.10.3-1)
sid: resolved (fixed in 1.10.3-1)
trixie: resolved (fixed in 1.10.3-1)
debian
CVE-2019-20024P4LOWCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20024 [MEDIUM] CVE-2019-20024: libsixel - A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel....
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2020-21677P4MEDIUMCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2020
CVE-2020-21677 [MEDIUM] CVE-2020-21677: libsixel - A heap-based buffer overflow in the sixel_encoder_output_without_macro function ...
A heap-based buffer overflow in the sixel_encoder_output_without_macro function in encoder.c of Libsixel 1.8.4 allows attackers to cause a denial of service (DOS) via converting a crafted PNG file into Sixel format.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1
debian
CVE-2020-21049P4MEDIUMCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2020
CVE-2020-21049 [MEDIUM] CVE-2020-21049: libsixel - An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows ...
An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2020-21048P4MEDIUMCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2020
CVE-2020-21048 [MEDIUM] CVE-2020-21048: libsixel - An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers ...
An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2022-29977P4MEDIUMCVSS 6.5fixed in libsixel 1:1.8.7-1 (forky)2022
CVE-2022-29977 [MEDIUM] CVE-2022-29977: libsixel - There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 ...
There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.8.7-1)
sid: resolved (fixed in 1:1.8.7-1)
trixie: open
debian
CVE-2019-20056P4LOWCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20056 [MEDIUM] CVE-2019-20056: libsixel - stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other produ...
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2022-29978P4MEDIUMCVSS 6.5fixed in libsixel 1:1.8.7-1 (forky)2022
CVE-2022-29978 [MEDIUM] CVE-2022-29978: libsixel - There is a floating point exception error in sixel_encoder_do_resize, encoder.c:...
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1:1.8.7-1)
sid: resolved (fixed in 1:1.8.7-1)
trixie: open
debian
CVE-2020-11721P4LOWCVSS 6.5fixed in libsixel 1.10.3-1 (bookworm)2020
CVE-2020-11721 [MEDIUM] CVE-2020-11721: libsixel - load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointe...
load_png in loader.c in libsixel.a in libsixel 1.8.6 has an uninitialized pointer leading to an invalid call to free, which can cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.10.3-1)
bullseye: open
forky: resolved (fixed in 1.10.3-1)
sid: resolved (fixed in 1.10.3-1)
trixie: resolved (fixed in 1.10.3-1)
debian
CVE-2019-20022P4LOWCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20022 [MEDIUM] CVE-2019-20022: libsixel - An invalid memory address dereference was discovered in load_pnm in frompnm.c in...
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2021-45340P4MEDIUMCVSS 6.5fixed in libsixel 1.10.5-1 (forky)2021
CVE-2021-45340 [MEDIUM] CVE-2021-45340: libsixel - In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the st...
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.10.5-1)
sid: resolved (fixed in 1.10.5-1)
trixie: resolved (fixed in 1.10.5-1)
debian
CVE-2018-19757P4MEDIUMCVSS 6.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19757 [MEDIUM] CVE-2018-19757: libsixel - There is a NULL pointer dereference at function sixel_helper_set_additional_mess...
There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2019-20023P4LOWCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20023 [MEDIUM] CVE-2019-20023: libsixel - A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1...
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2018-19759P4MEDIUMCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19759 [MEDIUM] CVE-2018-19759: libsixel - There is a heap-based buffer over-read at stb_image_write.h (function: stbi_writ...
There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2018-19763P4MEDIUMCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19763 [MEDIUM] CVE-2018-19763: libsixel - There is a heap-based buffer over-read at writer.c (function: write_png_to_file)...
There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2018-19756P4MEDIUMCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19756 [MEDIUM] CVE-2018-19756: libsixel - There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load)...
There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2019-3573P4LOWCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2019
CVE-2019-3573 [MEDIUM] CVE-2019-3573: libsixel - In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_i...
In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2018-19761P4MEDIUMCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19761 [MEDIUM] CVE-2018-19761: libsixel - There is an illegal address access at fromsixel.c (function: sixel_decode_raw_im...
There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2019-11024P4LOWCVSS 5.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-11024 [MEDIUM] CVE-2019-11024: libsixel - The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite ...
The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
← Previous2 / 2