First published: Thu Jul 13 2023(Updated: )
libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IJG libjpeg | <1.66 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-37836.
The severity of CVE-2023-37836 is medium.
The affected software of CVE-2023-37836 is Jpeg Libjpeg version up to exclusive 1.66.
This vulnerability can be exploited by attackers using a crafted file to cause a Denial of Service (DoS).
Currently, there is no known fix available for CVE-2023-37836. It is recommended to keep the software up to date and apply any patches or updates released by the vendor.