CVE-2022-31796: Medium severity ijg libjpeg vulnerability
libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-31796?
CVE-2022-31796 is rated as a moderate severity vulnerability due to the potential for heap-based buffer over-read which could lead to information leak.
How do I fix CVE-2022-31796?
To fix CVE-2022-31796, upgrade libjpeg to version 1.63 or later where the vulnerability has been addressed.
What causes CVE-2022-31796?
CVE-2022-31796 is caused by a heap-based buffer over-read in the HierarchicalBitmapRequester::FetchRegion function due to discrepancies in MCU size between allocation and usage.
Which software versions are affected by CVE-2022-31796?
CVE-2022-31796 specifically affects libjpeg version 1.63.
Is CVE-2022-31796 exploitable in the wild?
There is currently no public evidence indicating that CVE-2022-31796 is actively exploited in the wild, but it is recommended to apply the fix promptly.