First published: Fri Jun 10 2022(Updated: )
There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IJG libjpeg | <1.64 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-32978 is a vulnerability in libjpeg before version 1.64, which leads to an assertion failure in SingleComponentLSScan::ParseMCU via an empty JPEG-LS scan.
CVE-2022-32978 has a severity rating of 6.5 (medium).
The affected software is Jpeg Libjpeg before version 1.64.
To fix CVE-2022-32978, update your Jpeg Libjpeg software to version 1.64 or newer.
You can find more information about CVE-2022-32978 at the following references: [Reference 1](https://github.com/thorfdbg/libjpeg/commit/4746b577931e926a49e50de9720a4946de3069a7), [Reference 2](https://github.com/thorfdbg/libjpeg/issues/75).