You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
It seems different behavor with/without -fsanitize=address option.
When sanitizer is enabled and using POC5 (attached in the bugzilla page): https://github.com/saitoha/libsixel/blob/master/converters/malloc_stub.c#L45
malloc try to allcate with n = 11453255008 bytes. It seems too huge.
On the other hand, when sanitizer is disable the problem not happend.
CVE-2018-19759
https://nvd.nist.gov/vuln/detail/CVE-2018-19759
https://bugzilla.redhat.com/show_bug.cgi?id=1649202
The text was updated successfully, but these errors were encountered: