modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-12761.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "1.6.0" } ] } ]