#20721 closed enhancement (fixed)

libjxl-0.11.1

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 12.3
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Xi Ruoyao, 23 months ago

Priority: normal → elevated
  • Huffman lookup table size fix (#3871 - CVE-2024-11403)
  • Check height limit in modular trees. (#3943 - CVE-2024-11498)

comment:2 by Douglas R. Reno, 22 months ago

CVE-2024-11403 is a out-of-bounds write vulnerability in JxlEncoderAddJPEGFrame, which could lead to arbitrary code execution (or an application crash).

CVE-2024-11498 is a denial of service issue due to stack exhaustion

comment:3 by Douglas R. Reno, 22 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:4 by Douglas R. Reno, 22 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at d2ad7f9dfa8a4dcc93561efa9d2d7ff682419f59

SA-12.2-050 issued

Note: See TracTickets for help on using tickets.