Opened 5 months ago

Closed 5 months ago

#20721 closed enhancement (fixed)

libjxl-0.11.1

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 12.3
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Xi Ruoyao, 5 months ago

Priority: normalelevated
  • Huffman lookup table size fix (#3871 - CVE-2024-11403)
  • Check height limit in modular trees. (#3943 - CVE-2024-11498)

comment:2 by Douglas R. Reno, 5 months ago

CVE-2024-11403 is a out-of-bounds write vulnerability in JxlEncoderAddJPEGFrame, which could lead to arbitrary code execution (or an application crash).

CVE-2024-11498 is a denial of service issue due to stack exhaustion

comment:3 by Douglas R. Reno, 5 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: newassigned

comment:4 by Douglas R. Reno, 5 months ago

Resolution: fixed
Status: assignedclosed

Fixed at d2ad7f9dfa8a4dcc93561efa9d2d7ff682419f59

SA-12.2-050 issued

Note: See TracTickets for help on using tickets.