Debian Libsixel vulnerabilities
42 known vulnerabilities affecting debian/libsixel.
Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM16LOW19
Vulnerabilities
Page 2 of 3
CVE-2019-3574LOWCVSS 7.8fixed in libsixel 1.8.2-2 (bookworm)2019
CVE-2019-3574 [HIGH] CVE-2019-3574: libsixel - In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_...
In libsixel v1.8.2, there is a heap-based buffer over-read in the function load_jpeg() in the file loader.c, as demonstrated by img2sixel.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2019-20022LOWCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20022 [MEDIUM] CVE-2019-20022: libsixel - An invalid memory address dereference was discovered in load_pnm in frompnm.c in...
An invalid memory address dereference was discovered in load_pnm in frompnm.c in libsixel before 1.8.3.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-3573LOWCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2019
CVE-2019-3573 [MEDIUM] CVE-2019-3573: libsixel - In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_i...
In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2019-19777LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19777 [HIGH] CVE-2019-19777: libsixel - stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other produ...
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has a heap-based buffer over-read in stbi__load_main.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-19637LOWCVSS 9.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19637 [CRITICAL] CVE-2019-19637: libsixel - An issue was discovered in libsixel 1.8.2. There is an integer overflow in the f...
An issue was discovered in libsixel 1.8.2. There is an integer overflow in the function sixel_decode_raw_impl at fromsixel.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-19778LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19778 [HIGH] CVE-2019-19778: libsixel - An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-rea...
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer over-read in the function load_sixel at loader.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-20023LOWCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20023 [MEDIUM] CVE-2019-20023: libsixel - A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1...
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-11024LOWCVSS 5.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-11024 [MEDIUM] CVE-2019-11024: libsixel - The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite ...
The load_pnm function in frompnm.c in libsixel.a in libsixel 1.8.2 has infinite recursion.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-19638LOWCVSS 9.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19638 [CRITICAL] CVE-2019-19638: libsixel - An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow...
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function load_pnm at frompnm.c, due to an integer overflow.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-20024LOWCVSS 6.5fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20024 [MEDIUM] CVE-2019-20024: libsixel - A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel....
A heap-based buffer overflow was discovered in image_buffer_resize in fromsixel.c in libsixel before 1.8.4.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-19635LOWCVSS 9.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-19635 [CRITICAL] CVE-2019-19635: libsixel - An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow...
An issue was discovered in libsixel 1.8.2. There is a heap-based buffer overflow in the function sixel_decode_raw_impl at fromsixel.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-20140LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20140 [HIGH] CVE-2019-20140: libsixel - An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow...
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_out_code at fromgif.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-20205LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20205 [HIGH] CVE-2019-20205: libsixel - libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2019-20094LOWCVSS 8.8fixed in libsixel 1.8.6-1 (bookworm)2019
CVE-2019-20094 [HIGH] CVE-2019-20094: libsixel - An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow...
An issue was discovered in libsixel 1.8.4. There is a heap-based buffer overflow in the function gif_init_frame at fromgif.c.
Scope: local
bookworm: resolved (fixed in 1.8.6-1)
bullseye: resolved (fixed in 1.8.6-1)
forky: resolved (fixed in 1.8.6-1)
sid: resolved (fixed in 1.8.6-1)
trixie: resolved (fixed in 1.8.6-1)
debian
CVE-2018-19762HIGHCVSS 7.8fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19762 [HIGH] CVE-2018-19762: libsixel - There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_res...
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of service or possibly unspecified other impact.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-
debian
CVE-2018-19761MEDIUMCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19761 [MEDIUM] CVE-2018-19761: libsixel - There is an illegal address access at fromsixel.c (function: sixel_decode_raw_im...
There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2018-19757MEDIUMCVSS 6.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19757 [MEDIUM] CVE-2018-19757: libsixel - There is a NULL pointer dereference at function sixel_helper_set_additional_mess...
There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2018-19759MEDIUMCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19759 [MEDIUM] CVE-2018-19759: libsixel - There is a heap-based buffer over-read at stb_image_write.h (function: stbi_writ...
There is a heap-based buffer over-read at stb_image_write.h (function: stbi_write_png_to_mem) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2018-19763MEDIUMCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19763 [MEDIUM] CVE-2018-19763: libsixel - There is a heap-based buffer over-read at writer.c (function: write_png_to_file)...
There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian
CVE-2018-19756MEDIUMCVSS 5.5fixed in libsixel 1.8.2-2 (bookworm)2018
CVE-2018-19756 [MEDIUM] CVE-2018-19756: libsixel - There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load)...
There is a heap-based buffer over-read at stb_image.h (function: stbi__tga_load) in libsixel 1.8.2 that will cause a denial of service.
Scope: local
bookworm: resolved (fixed in 1.8.2-2)
bullseye: resolved (fixed in 1.8.2-2)
forky: resolved (fixed in 1.8.2-2)
sid: resolved (fixed in 1.8.2-2)
trixie: resolved (fixed in 1.8.2-2)
debian