First published: Fri Sep 09 2022(Updated: )
An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tesseract OCR | =5.0.0-alpha-20210401 | |
Leptonica | <1.80.0 | |
Debian GNU/Linux | =10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38266 is classified as a high severity vulnerability that can lead to Denial of Service.
To fix CVE-2022-38266, upgrade Leptonica to version 1.80.0 or later.
CVE-2022-38266 affects Leptonica versions up to 1.80.0, Tesseract 5.0.0-alpha-20210401, and Debian 10.0.
CVE-2022-38266 is an arithmetic exception vulnerability that can trigger a Denial of Service.
Using Tesseract with the vulnerable version of Leptonica may expose you to risks, so it is recommended to update.