CVE-2022-28471

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
05/05/2022
Last modified:
17/08/2023

Description

In ffjpeg (commit hash: caade60), the function bmp_load() in bmp.c contains an integer overflow vulnerability, which eventually results in the heap overflow in jfif_encode() in jfif.c. This is due to the incomplete patch for issue 38

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockcarry:ffjpeg:2021-12-06:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools