In Libsixel prior to and including v1.10.3, a NULL pointer dereference in the stb_image.h component of libsixel allows attackers to cause a denial of service (DOS) via a crafted PICT file.
The product dereferences a pointer that it expects to be valid but is NULL.
| Name | Vendor | Start Version | End Version | 
|---|---|---|---|
| Libsixel | Libsixel_project | * | 1.10.3 (including) | 
| Libsixel | Ubuntu | bionic | * | 
| Libsixel | Ubuntu | focal | * | 
| Libsixel | Ubuntu | impish | * | 
| Libsixel | Ubuntu | kinetic | * | 
| Libsixel | Ubuntu | lunar | * | 
| Libsixel | Ubuntu | mantic | * | 
| Libsixel | Ubuntu | oracular | * | 
| Libsixel | Ubuntu | trusty | * | 
| Libsixel | Ubuntu | xenial | * |