Description
In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/thorfdbg/libjpeg/commit/51c3241b6da39df30f016b63f43f31c4011222c7
Exploit, Issue Tracking, Third Party Advisory x_refsource_misc
https://github.com/thorfdbg/libjpeg/issues/74
Scores
CVSS v3
5.5
EPSS
0.0014
EPSS Percentile
33.3%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-476
Status
published
Products (1)
libjpeg_project/libjpeg
1.63
Published
Jun 02, 2022
Tracked Since
Feb 18, 2026