Vulnerability Details CVE-2023-0645
An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.7%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2023-0645
-
cpe:2.3:a:libjxl_project:libjxl:-
-
cpe:2.3:a:libjxl_project:libjxl:0.1
-
cpe:2.3:a:libjxl_project:libjxl:0.1.1
-
cpe:2.3:a:libjxl_project:libjxl:0.2
-
cpe:2.3:a:libjxl_project:libjxl:0.3
-
cpe:2.3:a:libjxl_project:libjxl:0.3.1
-
cpe:2.3:a:libjxl_project:libjxl:0.3.2
-
cpe:2.3:a:libjxl_project:libjxl:0.3.3
-
cpe:2.3:a:libjxl_project:libjxl:0.3.4
-
cpe:2.3:a:libjxl_project:libjxl:0.3.5
-
cpe:2.3:a:libjxl_project:libjxl:0.3.6
-
cpe:2.3:a:libjxl_project:libjxl:0.3.7
-
cpe:2.3:a:libjxl_project:libjxl:0.5
-
cpe:2.3:a:libjxl_project:libjxl:0.6
-
cpe:2.3:a:libjxl_project:libjxl:0.6.0
-
cpe:2.3:a:libjxl_project:libjxl:0.6.1
-
cpe:2.3:a:libjxl_project:libjxl:0.7.0
-
cpe:2.3:a:libjxl_project:libjxl:0.8.0