CVE-2022-31620

In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically coded sequential scan.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:libjpeg_project:libjpeg:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:04

Type Values Removed Values Added
References () https://github.com/thorfdbg/libjpeg/commit/ef4a29a62ab48b8dc235f4af52cfd6319eda9a6a - Patch, Third Party Advisory () https://github.com/thorfdbg/libjpeg/commit/ef4a29a62ab48b8dc235f4af52cfd6319eda9a6a - Patch, Third Party Advisory
References () https://github.com/thorfdbg/libjpeg/issues/70 - Exploit, Issue Tracking, Third Party Advisory () https://github.com/thorfdbg/libjpeg/issues/70 - Exploit, Issue Tracking, Third Party Advisory

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-119 CWE-617

Information

Published : 2022-05-25 21:15

Updated : 2024-11-21 07:04


NVD link : CVE-2022-31620

Mitre link : CVE-2022-31620

CVE.ORG link : CVE-2022-31620


JSON object : View

Products Affected

libjpeg_project

  • libjpeg
CWE
CWE-617

Reachable Assertion