An invalid read in the stb_image.h component of libsixel prior to v1.8.5 allows attackers to cause a denial of service (DOS) via a crafted PSD file.
[
{
"digest": {
"function_hash": "14053531760985046976932775092926153829",
"length": 167.0
},
"id": "CVE-2020-21049-300c1a47",
"signature_type": "Function",
"source": "https://github.com/saitoha/libsixel/commit/0b1e0b3f7b44233f84e5c9f512f8c90d6bbbe33d",
"deprecated": false,
"target": {
"function": "sixel_allocator_calloc",
"file": "src/allocator.c"
},
"signature_version": "v1"
},
{
"digest": {
"function_hash": "248279636798139373860926751670000785549",
"length": 241.0
},
"id": "CVE-2020-21049-7516b542",
"signature_type": "Function",
"source": "https://github.com/saitoha/libsixel/commit/0b1e0b3f7b44233f84e5c9f512f8c90d6bbbe33d",
"deprecated": false,
"target": {
"function": "sixel_allocator_malloc",
"file": "src/allocator.c"
},
"signature_version": "v1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"299830155393860697827618934141247146061",
"146241829523233735463078974435060176264",
"191065237130737033539251958551560897080",
"255871072765999720124756059089290237367",
"281717664013545157945889816801227351691",
"316609583128505174457879902511827517585",
"6672221964126041590966727542731475682",
"230878957094134071707425572935432296593",
"292521596394687844652728527156577949240",
"197698837200332871525583239750484894218",
"184766815279878921875648068209369119125",
"315197971923010764043084752149568680299",
"19596710656843220683553100070881730290"
]
},
"id": "CVE-2020-21049-b7c03e43",
"signature_type": "Line",
"source": "https://github.com/saitoha/libsixel/commit/0b1e0b3f7b44233f84e5c9f512f8c90d6bbbe33d",
"deprecated": false,
"target": {
"file": "src/allocator.c"
},
"signature_version": "v1"
},
{
"digest": {
"function_hash": "265876843441913872333024852228689490945",
"length": 171.0
},
"id": "CVE-2020-21049-eca8721e",
"signature_type": "Function",
"source": "https://github.com/saitoha/libsixel/commit/0b1e0b3f7b44233f84e5c9f512f8c90d6bbbe33d",
"deprecated": false,
"target": {
"function": "sixel_allocator_realloc",
"file": "src/allocator.c"
},
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-21049.json"
"2026-04-11T09:46:20Z"