CVE-2023-35790

Severity CVSS v4.0:
Pending analysis
Type:
CWE-191 Integer Underflow (Wrap or Wraparound)
Publication date:
16/06/2023
Last modified:
26/06/2023

Description

An issue was discovered in dec_patch_dictionary.cc in libjxl before 0.8.2. An integer underflow in patch decoding can lead to a denial of service, such as an infinite loop.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:* 0.8.2 (excluding)