In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
{ "binaries": [ { "binary_name": "libsixel-bin", "binary_version": "1.8.2-2.1" }, { "binary_name": "libsixel-dev", "binary_version": "1.8.2-2.1" }, { "binary_name": "libsixel-examples", "binary_version": "1.8.2-2.1" }, { "binary_name": "libsixel1", "binary_version": "1.8.2-2.1" } ] }
{ "binaries": [ { "binary_name": "libsixel-bin", "binary_version": "1.10.3-3build1" }, { "binary_name": "libsixel-dev", "binary_version": "1.10.3-3build1" }, { "binary_name": "libsixel-examples", "binary_version": "1.10.3-3build1" }, { "binary_name": "libsixel1", "binary_version": "1.10.3-3build1" } ] }