CVE-2023-37836: Medium severity jpeg libjpeg vulnerability
Published Jul 13, 2023
·Updated
libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Affected Software
1 affected component
jpeg libjpeg<1.66
Remediation
Patch Available
Event History
Jul 13, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
11:15 PM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-37836.
2
What is the severity of CVE-2023-37836?
The severity of CVE-2023-37836 is medium.
3
What is the affected software of CVE-2023-37836?
The affected software of CVE-2023-37836 is Jpeg Libjpeg version up to exclusive 1.66.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers using a crafted file to cause a Denial of Service (DoS).
5
Is there a fix available for CVE-2023-37836?
Currently, there is no known fix available for CVE-2023-37836. It is recommended to keep the software up to date and apply any patches or updates released by the vendor.