Vulnerability Details CVE-2021-45928
libjxl b02d6b9, as used in libvips 8.11 through 8.11.2 and other products, has an out-of-bounds write in jxl::ModularFrameDecoder::DecodeGroup (called from jxl::FrameDecoder::ProcessACGroup and jxl::ThreadPool::RunCallState<jxl::FrameDecoder::ProcessSections).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.4%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 2.1
Products affected by CVE-2021-45928
-
cpe:2.3:a:libjxl_project:libjxl:-
-
cpe:2.3:a:libjxl_project:libjxl:0.1
-
cpe:2.3:a:libjxl_project:libjxl:0.1.1
-
cpe:2.3:a:libjxl_project:libjxl:0.2
-
cpe:2.3:a:libjxl_project:libjxl:0.3
-
cpe:2.3:a:libjxl_project:libjxl:0.3.1
-
cpe:2.3:a:libjxl_project:libjxl:0.3.2
-
cpe:2.3:a:libjxl_project:libjxl:0.3.3
-
cpe:2.3:a:libjxl_project:libjxl:0.3.4
-
cpe:2.3:a:libjxl_project:libjxl:0.3.5
-
cpe:2.3:a:libjxl_project:libjxl:0.3.6
-
cpe:2.3:a:libjxl_project:libjxl:0.3.7
-
cpe:2.3:a:libjxl_project:libjxl:0.5
-
cpe:2.3:a:libjxl_project:libjxl:0.6
-
cpe:2.3:a:libjxl_project:libjxl:0.6.0