chafa is vulnerable to denial of service. The vulnerability exists due to a NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c.
github.com/hpjansson/chafa/commit/e4b777c7b7c144cd16a0ea96108267b1004fe6c9
huntr.dev/bounties/104d8c5d-cac5-4baa-9ac9-291ea0bcab95
lists.fedoraproject.org/archives/list/[email protected]/message/3PLHKTQYK6AO3M5NAVM3CDVQTZZS6MCO/
lists.fedoraproject.org/archives/list/[email protected]/message/DIOAZPITFL2Y7Y6KHCZ4OIK7P7KWFN22/
lists.fedoraproject.org/archives/list/[email protected]/message/L54UEP5S254VP5FZWGFPHLTPMFJVOGYT/
security-tracker.debian.org/tracker/CVE-2022-1507