CVE-2021-22563 - log back

CVE-2021-22563 edited at 01 Nov 2021 15:00:23
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
Description
+ Invalid JPEG XL images using libjxl before version 0.6.1 can cause an out of bounds access on a std::vector<std::vector<T>> when rendering splines. The OOB read access can either lead to a segfault, or rendering splines based on other process memory.
References
+ https://github.com/libjxl/libjxl/issues/735
+ https://github.com/libjxl/libjxl/pull/757
+ https://github.com/libjxl/libjxl/commit/b0b39694d8ba6eb031eae217fcae488ce7403ae7
Notes
CVE-2021-22563 created at 01 Nov 2021 14:36:39