Open waugustus opened 2 years ago
Can you report the issue to the new upstream at https://github.com/libsixel/libsixel ?
Maybe this project should as well be archived if it's not anymore the main upstream repository for libsixel.
Can you report the issue to the new upstream at https://github.com/libsixel/libsixel ?
OK, and thank you for your suggestion.
CVE-2022-29978 assigned.
Description
There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
Version
img2sixel 1.8.6, commit id https://github.com/saitoha/libsixel/commit/6a5be8b72d84037b83a5ea838e17bcf372ab1d5f (Tue Jan 14 02:27:00 2020 +0900)
Reproduction
poc.zip
Platform