CVE-2019-3573 (NVD)

2019-01-02

In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.

Products Libsixel
Type Uncontrolled Resource Consumption (CWE-400)
First patch - None (likely due to unavailable code)
Links https://github.com/saitoha/libsixel/issues/83
https://github.com/TeamSeri0us/pocs/tree/master/libsixel