Out-of-bounds Read Affecting jpeg-xl package, versions <0.8.2-4


Severity

Recommended
0.0
critical
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.17% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-JPEGXL-5683388
  • published15 Apr 2023
  • disclosed11 Apr 2023

Introduced: 11 Apr 2023

CVE-2023-0645  (opens in a new tab)
CWE-125  (opens in a new tab)

How to fix?

Upgrade Debian:13 jpeg-xl to version 0.8.2-4 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream jpeg-xl package and not the jpeg-xl package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159

CVSS Scores

version 3.1