9.1
CVSSv3

CVE-2023-0645

Published: 11/04/2023 Updated: 18/04/2023
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libjxl project libjxl

Vendor Advisories

Debian Bug report logs - #1034722 jpeg-xl: CVE-2023-0645 Package: src:jpeg-xl; Maintainer for src:jpeg-xl is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Sat, 22 Apr 2023 17:33:05 UTC Severity: important Tags: security, upstream ...