Echo: libcaca: security update to 0.99.beta20-5+e1

high Tenable Self-Hosted Container Security Plugin ID 458470

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in
libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-bounds write
(heap overflow) by supplying a crafted file in the "caca" format. Depending on the build configuration and
memory allocator, this may lead to memory corruption or remote code execution. This is the same
vulnerability as CVE-2021-3410 but the fix at that time was not fully correct. Commit
fb77acff9ba6bb01d53940da34fb10f20b156a23 fixes this vulnerability. (CVE-2026-42046)

Solution

Update the libcaca library and its related packages to version 0.99.beta20-5+e1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-42046

Plugin Details

Severity: High

ID: 458470

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.96

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-42046

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/11/2026

Reference Information

CVE: CVE-2026-42046