CVE-2022-37768: High severity ijg libjpeg vulnerability
Published Aug 18, 2022
·Updated
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
Affected Software
1 affected component
jpeg libjpeg
Event History
Aug 18, 2022
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
Description
Frequently Asked Questions
1
What is CVE-2022-37768?
CVE-2022-37768 is a vulnerability in libjpeg commit 281daa9 that allows an attacker to cause an infinite loop through the Frame::ParseTrailer component.
2
How severe is CVE-2022-37768?
CVE-2022-37768 has a severity rating of 7.5, which is considered high.
3
What software is affected by CVE-2022-37768?
The libjpeg software is affected by CVE-2022-37768.
4
How can I fix CVE-2022-37768?
At the moment, there is no specific fix available for CVE-2022-37768. It is recommended to update to a patched version or follow any mitigation steps provided by the software vendor.
5
Where can I find more information about CVE-2022-37768?
You can find more information about CVE-2022-37768 at the following reference link: <https://github.com/thorfdbg/libjpeg/issues/77>