Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 783516 - media-libs/libsixel: stack buffer overflow (CVE-2020-36120)
Summary: media-libs/libsixel: stack buffer overflow (CVE-2020-36120)
Status: RESOLVED DUPLICATE of bug 717254
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/saitoha/libsixel/i...
Whiteboard: B3 [upstream]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-04-17 23:44 UTC by John Helmert III
Modified: 2021-09-18 14:27 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-04-17 23:44:18 UTC
CVE-2020-36120:

Buffer Overflow in the "sixel_encoder_encode_bytes" function of Libsixel v1.8.6 allows attackers to cause a Denial of Service (DoS).


Looks like there's a bunch of security issues both open and closed too.
Comment 1 NATTkA bot gentoo-dev 2021-07-29 17:23:00 UTC Comment hidden (obsolete)
Comment 2 NATTkA bot gentoo-dev 2021-07-29 17:31:20 UTC Comment hidden (obsolete)
Comment 3 NATTkA bot gentoo-dev 2021-07-29 17:39:17 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:47:26 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 18:03:23 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 18:11:40 UTC
Package list is empty or all packages have requested keywords.
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-09-18 14:27:07 UTC
Adding this CVE to the other bug to reduce complexity.

*** This bug has been marked as a duplicate of bug 717254 ***