ALT-PU-2023-1180-2
Closed vulnerabilities
Published: 2025-09-26
Modified: 2026-03-04
Modified: 2026-03-04
BDU:2025-11754
Уязвимость библиотеки Libjxl, связанная с чтением вне границ памяти, позволяющая нарушителю получить доступ к конфиденциальной информации
Severity: CRITICAL (9.1)Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Severity: CRITICAL (9.4)Vector: AV:N/AC:L/Au:N/C:C/I:N/A:C
References:
Published: 2023-04-11
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2023-0645
An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159
Severity: CRITICAL (9.1)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
References:
