Описание
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
A flaw was found in libjxl, an image processing library. This heap buffer overflow vulnerability could potentially allow a remote attacker to cause a denial of service. The flaw occurs when processing specially crafted PBM (Portable Bitmap) images, primarily impacting applications that handle untrusted image content.
Отчет
This Important heap buffer overflow in libjxl occurs when processing specially crafted PBM images. The vulnerability primarily impacts applications that handle untrusted image content, requiring user interaction to trigger the flaw. This is considered Important due to the potential for denial of service, even with user interaction.
Меры по смягчению последствий
Upstream has fixed this issue in PR #4338. To mitigate this flaw update to a libjxl version containing the fix once it becomes available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox | Affected | ||
| Red Hat Enterprise Linux 10 | thunderbird | Affected | ||
| Red Hat Enterprise Linux 8 | thunderbird | Affected | ||
| Red Hat Enterprise Linux 9 | thunderbird | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.6 High
CVSS3
Связанные уязвимости
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM im ...
EPSS
7.6 High
CVSS3