CVE-2022-35166: Medium severity ijg libjpeg vulnerability
Published Aug 18, 2022
·Updated
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
Affected Software
1 affected component
jpeg libjpeg=2022-06-15
Event History
Aug 18, 2022
CVE Published
via MITRE·04:49 AM
Data Sourced
via MITRE·04:49 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-35166?
CVE-2022-35166 is considered a medium severity vulnerability due to the potential for denial of service caused by an infinite loop.
2
How do I fix CVE-2022-35166?
To fix CVE-2022-35166, update to the latest version of libjpeg that addresses this issue.
3
What impact does CVE-2022-35166 have on libjpeg users?
CVE-2022-35166 can lead to a denial of service, affecting application availability using libjpeg.
4
Is my system affected by CVE-2022-35166?
Your system may be affected by CVE-2022-35166 if it uses libjpeg version 2022-06-15 or earlier.
5
What components are involved in CVE-2022-35166?
CVE-2022-35166 involves the JPEG::ReadInternal component of libjpeg, which is responsible for reading JPEG images.