CVE-2022-32978: Medium severity ijg libjpeg vulnerability
Published Jun 10, 2022
·Updated
There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.
Affected Software
1 affected component
jpeg libjpeg<1.64
Remediation
Event History
Jun 10, 2022
CVE Published
via MITRE·02:49 PM
Data Sourced
via MITRE·02:49 PM
Description
Frequently Asked Questions
1
What is CVE-2022-32978?
CVE-2022-32978 is a vulnerability in libjpeg before version 1.64, which leads to an assertion failure in SingleComponentLSScan::ParseMCU via an empty JPEG-LS scan.
2
How severe is CVE-2022-32978?
CVE-2022-32978 has a severity rating of 6.5 (medium).
3
What software is affected by CVE-2022-32978?
The affected software is Jpeg Libjpeg before version 1.64.
4
How can I fix CVE-2022-32978?
To fix CVE-2022-32978, update your Jpeg Libjpeg software to version 1.64 or newer.
5
Where can I find more information about CVE-2022-32978?
You can find more information about CVE-2022-32978 at the following references: [Reference 1](https://github.com/thorfdbg/libjpeg/commit/4746b577931e926a49e50de9720a4946de3069a7), [Reference 2](https://github.com/thorfdbg/libjpeg/issues/75).