Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 832049 (CVE-2020-36123, CVE-2021-40656, CVE-2021-41715, CVE-2021-45340, CVE-2021-46700, CVE-2022-27044, CVE-2022-27046, CVE-2022-29977, CVE-2022-29978) - media-libs/libsixel: multiple vulnerabilities
Summary: media-libs/libsixel: multiple vulnerabilities
Status: CONFIRMED
Alias: CVE-2020-36123, CVE-2021-40656, CVE-2021-41715, CVE-2021-45340, CVE-2021-46700, CVE-2022-27044, CVE-2022-27046, CVE-2022-29977, CVE-2022-29978
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor
Assignee: Gentoo Security
URL: https://github.com/libsixel/libsixel/...
Whiteboard: B3 [upstream]
Keywords:
Depends on:
Blocks: CVE-2022-27938
  Show dependency tree
 
Reported: 2022-01-25 15:03 UTC by filip ambroz
Modified: 2024-09-16 04:27 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description filip ambroz 2022-01-25 15:03:13 UTC
In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
Comment 1 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-01-25 15:50:15 UTC
"so this wasn't even supposed to be using STB, except for a bug where the compilie-time config wasn't being checked correctly. it now ought use libpng when present, and i'm thinking we ought yank out this vendored library."

Heh.

libsixel has a stable version so switching to B, and marking as [upstream/ebuild] since there are patches available if the maintainer deems it necessary to import them.
Comment 2 filip ambroz 2022-02-19 22:32:12 UTC
[CVE-2021-46700]
In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.

URL: https://github.com/saitoha/libsixel/issues/158
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-02-20 02:39:05 UTC
CVE-2021-46700 (https://github.com/saitoha/libsixel/issues/158):

In libsixel 1.8.6, sixel_encoder_output_without_macro (called from sixel_encoder_encode_frame in encoder.c) has a double free.
Comment 4 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-13 14:09:17 UTC
CVE-2020-36123 (https://github.com/saitoha/libsixel/issues/144):

saitoha libsixel v1.8.6 was discovered to contain a double free via the component sixel_chunk_destroy at /root/libsixel/src/chunk.c.
Comment 5 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-04-09 17:11:01 UTC
CVE-2021-40656 (https://github.com/libsixel/libsixel/issues/25):

libsixel before 1.10 is vulnerable to Buffer Overflow in libsixel/src/quant.c:867.
Comment 6 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-04-09 23:33:47 UTC
CVE-2021-41715 (https://github.com/libsixel/libsixel/issues/27):

libsixel 1.10.0 is vulnerable to Use after free in libsixel/src/dither.c:379.

CVE-2022-27044 (https://github.com/saitoha/libsixel/issues/156):

libsixel 1.8.6 is affected by Buffer Overflow in libsixel/src/quant.c:876.

CVE-2022-27046 (https://github.com/saitoha/libsixel/issues/157):

libsixel 1.8.6 suffers from a Heap Use After Free vulnerability in in libsixel/src/dither.c:388.

The libsixel/libsixel issue is fixed. The saitoha repository remains
unresponsive. More investigation is needed to determine if the saitoha
vulnerabilities affect the libsixel/libsixel repository.
Comment 7 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-05-12 02:52:29 UTC
CVE-2022-29977 (https://github.com/saitoha/libsixel/issues/165):

There is an assertion failure error in stbi__jpeg_huff_decode, stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.

CVE-2022-29978 (https://github.com/saitoha/libsixel/issues/166):

There is a floating point exception error in sixel_encoder_do_resize, encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted JPEG file.
Comment 8 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2024-09-16 04:27:00 UTC
(In reply to John Helmert III from comment #7)
> CVE-2022-29977 (https://github.com/saitoha/libsixel/issues/165):
> 
> There is an assertion failure error in stbi__jpeg_huff_decode,
> stb_image.h:1894 in libsixel img2sixel 1.8.6. Remote attackers could
> leverage this vulnerability to cause a denial-of-service via a crafted JPEG
> file.
> 
> CVE-2022-29978 (https://github.com/saitoha/libsixel/issues/166):
> 
> There is a floating point exception error in sixel_encoder_do_resize,
> encoder.c:633 in libsixel img2sixel 1.8.6. Remote attackers could leverage
> this vulnerability to cause a denial-of-service via a crafted JPEG file.

Doesn't look like these two are fixed.