CVE-2022-38266: Divide by Zero
Published Sep 9, 2022
·Updated
An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
Affected Software
3 affected components
Tesseract Project Tesseract=5.0.0-alpha-20210401
Leptonica Leptonica<1.80.0
Debian Debian Linux=10.0
Remediation
Event History
Sep 9, 2022
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-38266?
CVE-2022-38266 is classified as a high severity vulnerability that can lead to Denial of Service.
2
How do I fix CVE-2022-38266?
To fix CVE-2022-38266, upgrade Leptonica to version 1.80.0 or later.
3
Which software is affected by CVE-2022-38266?
CVE-2022-38266 affects Leptonica versions up to 1.80.0, Tesseract 5.0.0-alpha-20210401, and Debian 10.0.
4
What type of vulnerability is CVE-2022-38266?
CVE-2022-38266 is an arithmetic exception vulnerability that can trigger a Denial of Service.
5
Can I still use Tesseract with CVE-2022-38266?
Using Tesseract with the vulnerable version of Leptonica may expose you to risks, so it is recommended to update.