First published: Thu Aug 18 2022(Updated: )
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IJG libjpeg |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-37768 is a vulnerability in libjpeg commit 281daa9 that allows an attacker to cause an infinite loop through the Frame::ParseTrailer component.
CVE-2022-37768 has a severity rating of 7.5, which is considered high.
The libjpeg software is affected by CVE-2022-37768.
At the moment, there is no specific fix available for CVE-2022-37768. It is recommended to update to a patched version or follow any mitigation steps provided by the software vendor.
You can find more information about CVE-2022-37768 at the following reference link: <https://github.com/thorfdbg/libjpeg/issues/77>