
Cloud Vulnerability DB
A community-led vulnerabilities database
A buffer overflow vulnerability (CVE-2021-30499) was discovered in libcaca's export.c file, specifically in the export_troff function. The vulnerability was reported on April 7, 2021, and affects the libcaca library, which provides color text drawing and image-to-text conversion capabilities (GitHub Issue, NVD).
The vulnerability is classified as a global buffer overflow with a CVSS v3.1 base score of 7.8 (HIGH). The attack vector is Local (AV:L), with Low attack complexity (AC:L), requiring no privileges (PR:N) but needing user interaction (UI:R). The scope is Unchanged (S:U) with High impact on Confidentiality, Integrity, and Availability (C:H/I:H/A:H) (NVD).
The buffer overflow vulnerability can lead to memory corruption and potentially other serious consequences, including system crashes or arbitrary code execution (GitHub Issue, NVD).
The vulnerability requires user interaction to be exploited and has been demonstrated through a proof-of-concept exploit. The issue was discovered using libfuzz test library API and can be triggered through specially crafted input to the export_troff function (GitHub Issue).
The vulnerability has been fixed in libcaca version 0.99.beta20. Multiple distributions have released security updates, including Fedora 34, 35, and 36 (version 0.99-0.59.beta20) and Debian 10 (version 0.99.beta19-2.1+deb10u1) (Fedora Update, Debian Update).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."