CVE-2023-0645: Out of Bounds read in libjxl
An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libjxlto a version that resolves this vulnerability.Fixed in 0.8.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2023-0645
Event History
Frequently Asked Questions
What is the severity of CVE-2023-0645?
CVE-2023-0645 has a moderate severity due to potential out of bounds read vulnerabilities.
How do I fix CVE-2023-0645?
To fix CVE-2023-0645, upgrade libjxl to version 0.8.1 or later.
What can happen if CVE-2023-0645 is exploited?
Exploitation of CVE-2023-0645 could lead to data leaks or application crashes due to out of bounds reads.
Which versions of libjxl are affected by CVE-2023-0645?
CVE-2023-0645 affects all versions of libjxl prior to 0.8.1.
Is there a known exploit for CVE-2023-0645?
As of now, there are no publicly known exploits specifically targeting CVE-2023-0645.