NA

CVE-2023-35790

Published: 16/06/2023 Updated: 26/06/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An issue exists in dec_patch_dictionary.cc in libjxl prior to 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop.

Vulnerable Product Search on Vulmon Subscribe to Product

libjxl project libjxl

Vendor Advisories

Debian Bug report logs - #1055306 jpeg-xl: CVE-2023-35790 Package: src:jpeg-xl; Maintainer for src:jpeg-xl is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Fri, 3 Nov 2023 19:27:06 UTC Severity: important Tags: security, upstream ...
DescriptionThe MITRE CVE dictionary describes this issue as: An issue was discovered in dec_patch_dictionarycc in libjxl before 082 An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop ...