Bug 1197580 - (CVE-2022-27938) VUL-1: CVE-2022-27938: libsixel: reachable assertion in stbi__create_png_image_raw
(CVE-2022-27938)
VUL-1: CVE-2022-27938: libsixel: reachable assertion in stbi__create_png_imag...
Status: NEW
Classification: openSUSE
Product: openSUSE Tumbleweed
Classification: openSUSE
Component: Security
Current
Other Other
: P4 - Low : Normal (vote)
: ---
Assigned To: Enrico Belleri
Security Team bot
https://smash.suse.de/issue/327304/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-03-28 08:45 UTC by Thomas Leroy
Modified: 2022-03-28 09:15 UTC (History)
0 users

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas Leroy 2022-03-28 08:45:09 UTC
CVE-2022-27938

stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other
products, has a reachable assertion in stbi__create_png_image_raw.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-27938
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27938
https://github.com/saitoha/libsixel/issues/163
http://www.cvedetails.com/cve/CVE-2022-27938/