Integer Underflow in libjxl Leads to DoS Risks
CVE-2023-35790

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
16 June 2023

What is CVE-2023-35790?

An integer underflow issue can occur in the dec_patch_dictionary.cc file of libjxl versions prior to 0.8.2. This vulnerability leads to improper patch decoding, which can cause the software to enter an infinite loop, resulting in denial of service. Users are advised to update to the latest version to ensure protection against such exploitation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.