Buffer Overflow Vulnerability in JPEG XL Decoder by libjxl
CVE-2024-11498

7.5HIGH

Key Information:

Vendor

libjxl

Vendor
CVE Published:
25 November 2024

What is CVE-2024-11498?

A stack buffer overflow exists in the JPEG XL decoder of libjxl, which can be exploited by specially-crafted files. This vulnerability may lead to excessive stack usage, potentially exhausting memory resources. Attackers can create files designed to overload the stack, resulting in significant resource drain. Users are advised to update to versions subsequent to commit 65fbec56bc578b6b6ee02a527be70787bbd053b0 for mitigation.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.