Описание
Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function
A flaw was found in libjxl. This buffer overflow vulnerability allows a local attacker to obtain sensitive information. The flaw occurs within the DecodeImageAPNG function, which can lead to unauthorized disclosure of data.
Отчет
Red Hat ships libjxl as a bundled component within Firefox and Thunderbird. The vulnerable code path is in the APNG decoder (DecodeImageAPNG), which is part of the extras module used by command-line tools. Firefox and Thunderbird have their own native APNG implementation and may not invoke libjxl's APNG decoder, limiting the practical exploitability of this flaw in Red Hat products.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | firefox | Fix deferred | ||
| Red Hat Enterprise Linux 10 | thunderbird | Fix deferred | ||
| Red Hat Enterprise Linux 8 | thunderbird | Fix deferred | ||
| Red Hat Enterprise Linux 9 | thunderbird | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5 Medium
CVSS3
Связанные уязвимости
Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function
Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function
Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a l ...
Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function
5 Medium
CVSS3