From b9fc63c20df1fdeead24c989c4aca4090830f9d4 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Tue, 1 Nov 2022 03:06:32 +0000 Subject: gentoo auto-resync : 01:11:2022 - 03:06:31 --- metadata/glsa/glsa-202210-36.xml | 42 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 42 insertions(+) create mode 100644 metadata/glsa/glsa-202210-36.xml (limited to 'metadata/glsa/glsa-202210-36.xml') diff --git a/metadata/glsa/glsa-202210-36.xml b/metadata/glsa/glsa-202210-36.xml new file mode 100644 index 000000000000..04ac36eb67fd --- /dev/null +++ b/metadata/glsa/glsa-202210-36.xml @@ -0,0 +1,42 @@ + + + + libjxl: Denial of Service + A vulnerability has been found in libjxl which could result in denial of service. + libjxl + 2022-10-31 + 2022-10-31 + 856037 + remote + + + 0.7.0_pre20220825 + 0.7.0_pre20220825 + + + +

libjxl is the JPEG XL image format reference implementation.

+
+ +

libjxl contains an unecessary assertion in jxl::LowMemoryRenderPipeline::Init.

+
+ +

An attacker can cause a denial of service of the libjxl process via a crafted input file.

+
+ +

There is no known workaround at this time.

+
+ +

All users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=media-libs/libjxl-0.7.0_pre20220825" + +
+ + CVE-2022-34000 + + ajak + ajak +
\ No newline at end of file -- cgit v1.2.3