First published: Thu Aug 18 2022(Updated: )
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IJG libjpeg | =2022-06-15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35166 is considered a medium severity vulnerability due to the potential for denial of service caused by an infinite loop.
To fix CVE-2022-35166, update to the latest version of libjpeg that addresses this issue.
CVE-2022-35166 can lead to a denial of service, affecting application availability using libjpeg.
Your system may be affected by CVE-2022-35166 if it uses libjpeg version 2022-06-15 or earlier.
CVE-2022-35166 involves the JPEG::ReadInternal component of libjpeg, which is responsible for reading JPEG images.