4.8
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixel_debug_print_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is identified as 316c086e79d66b62c0c4bc66229ee894e4fdb7d1. Applying a patch is advised to resolve this issue.
Basic Information
ID
CVE-2025-9300
Source
VulDB
Published
Aug 21, 2025 at 13:02
Affected Product
Vendor
saitoha
Product
libsixel
Version
1.10.0
Affected Versions
saitoha libsixel 1.10.0
saitoha libsixel 1.10.1
saitoha libsixel 1.10.2
saitoha libsixel 1.10.3
saitoha libsixel 1.10.1
saitoha libsixel 1.10.2
saitoha libsixel 1.10.3