In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
References
| Link | Resource |
|---|---|
| https://github.com/libsixel/libsixel/issues/51 | Exploit Issue Tracking Patch Third Party Advisory |
| https://github.com/libsixel/libsixel/issues/51 | Exploit Issue Tracking Patch Third Party Advisory |
Configurations
History
24 Apr 2026, 13:35
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:libsixel:libsixel:*:*:*:*:*:*:*:* | |
| First Time |
Libsixel
Libsixel libsixel |
21 Nov 2024, 06:32
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/libsixel/libsixel/issues/51 - Exploit, Issue Tracking, Patch, Third Party Advisory |
Information
Published : 2022-01-25 12:15
Updated : 2026-04-24 13:35
NVD link : CVE-2021-45340
Mitre link : CVE-2021-45340
CVE.ORG link : CVE-2021-45340
JSON object : View
Products Affected
libsixel
- libsixel
CWE
CWE-476
NULL Pointer Dereference
