Out of Bounds read in libjxl
CVE-2023-0645

5.3MEDIUM

Key Information:

Vendor

Libjxl

Status
Vendor
CVE Published:
11 April 2023

What is CVE-2023-0645?

An out of bounds read vulnerability has been identified in the Exif handler of libjxl, a library utilized for image processing. This weakness allows an attacker to exploit specially crafted image files, potentially leading to unauthorized access to sensitive memory locations. Users are advised to upgrade to version 0.8.1 or later to secure their systems against potential exploitation. For more details, please refer to the commit links for the recommended updates.

Affected Version(s)

Libjxl 0.7.0 < 0.8.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.