CVE Vulnerabilities

CVE-2019-3573

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Jan 02, 2019 | Modified: Aug 24, 2020
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

In libsixel v1.8.2, there is an infinite loop in the function sixel_decode_raw_impl() in the file fromsixel.c, as demonstrated by sixel2png.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Libsixel Libsixel_project 1.8.2 (including) 1.8.2 (including)
Libsixel Ubuntu bionic *
Libsixel Ubuntu cosmic *
Libsixel Ubuntu disco *
Libsixel Ubuntu eoan *
Libsixel Ubuntu esm-apps/bionic *
Libsixel Ubuntu esm-apps/xenial *
Libsixel Ubuntu upstream *
Libsixel Ubuntu xenial *

References