An issue in the dither.c component of libsixel prior to v1.8.4 allows attackers to cause a denial of service (DOS) via a crafted PNG file.
[
{
"id": "CVE-2020-21048-3f5e5c8e",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"target": {
"file": "src/dither.c",
"function": "sixel_dither_new"
},
"digest": {
"function_hash": "219832859337229444931238207892599109504",
"length": 1607.0
},
"source": "https://github.com/saitoha/libsixel/commit/cb373ab6614c910407c5e5a93ab935144e62b037"
},
{
"id": "CVE-2020-21048-b2b72c87",
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "src/dither.c"
},
"digest": {
"line_hashes": [
"199361631072483740361989714307393008478",
"291343961692008382086549080687427033920",
"16784547706756229315325119660300077615",
"101018793880447773360178885930836492685",
"69736891406652933996193619171756760618",
"254643536321277286518119263644437622942",
"115812485349409838505546949009351511461"
],
"threshold": 0.9
},
"source": "https://github.com/saitoha/libsixel/commit/cb373ab6614c910407c5e5a93ab935144e62b037"
}
]