There is an illegal READ memory access at caca/dither.c (function getrgbadefault) in libcaca 0.99.beta19 for the default bpp case.
{ "vanir_signatures": [ { "id": "CVE-2018-20546-16db8665", "target": { "file": "caca/dither.c" }, "source": "https://github.com/cacalabs/libcaca/commit/1022d97496c7899e8641515af363381b31ae2f05", "signature_type": "Line", "digest": { "line_hashes": [ "173697194705099104683245377240136433543", "127033609259635894559715003375059074023", "249858520968027005030518387805073278911", "278457499550985249528788813404705222476", "26662475878361700816840939041688976160" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1" } ] }