There is a heap-based buffer over-read at stbimagewrite.h (function: stbiwritepngtomem) in libsixel 1.8.2 that will cause a denial of service.
{ "urgency": "not yet assigned" }