CVE-2022-31620

In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically coded sequential scan.
References
Link Resource
https://github.com/thorfdbg/libjpeg/commit/ef4a29a62ab48b8dc235f4af52cfd6319eda9a6a Patch Third Party Advisory
https://github.com/thorfdbg/libjpeg/issues/70 Exploit Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:libjpeg_project:libjpeg:*:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-119 CWE-617

19 Jul 2022, 17:15

Type Values Removed Values Added
CPE cpe:2.3:a:ijg:libjpeg:*:*:*:*:*:*:*:* cpe:2.3:a:libjpeg_project:libjpeg:*:*:*:*:*:*:*:*
References (MISC) https://github.com/thorfdbg/libjpeg/issues/70 - Exploit, Third Party Advisory (MISC) https://github.com/thorfdbg/libjpeg/issues/70 - Exploit, Issue Tracking, Third Party Advisory

07 Jun 2022, 15:46

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 6.5
CPE cpe:2.3:a:ijg:libjpeg:*:*:*:*:*:*:*:*
References (MISC) https://github.com/thorfdbg/libjpeg/issues/70 - (MISC) https://github.com/thorfdbg/libjpeg/issues/70 - Exploit, Third Party Advisory
References (MISC) https://github.com/thorfdbg/libjpeg/commit/ef4a29a62ab48b8dc235f4af52cfd6319eda9a6a - (MISC) https://github.com/thorfdbg/libjpeg/commit/ef4a29a62ab48b8dc235f4af52cfd6319eda9a6a - Patch, Third Party Advisory
CWE CWE-119

25 May 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-25 21:15

Updated : 2024-02-04 22:29


NVD link : CVE-2022-31620

Mitre link : CVE-2022-31620

CVE.ORG link : CVE-2022-31620


JSON object : View

Products Affected

libjpeg_project

  • libjpeg
CWE
CWE-617

Reachable Assertion