Out-of-Bounds Write Vulnerability in libvips by Google
CVE-2021-45928

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
1 January 2022

What is CVE-2021-45928?

An out-of-bounds write vulnerability has been identified in libjxl's ModularFrameDecoder component, utilized in libvips. Specifically, flaws occur in the DecodeGroup function, which is invoked during the processing of AC groups in image files. This vulnerability could potentially be exploited to cause unintended behavior during image manipulation, posing risks such as data corruption or denial of service. Users of libvips should review affected versions and apply necessary updates to mitigate this risk.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.