libjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding a malicous APNG file using cjxl, an attacker can trigger a denial of service.
References
Link Resource
https://github.com/libjxl/libjxl/commit/7dfa400ded53919d986c5d3d23446a09e0cf481b Patch Third Party Advisory
https://github.com/libjxl/libjxl/issues/308 Exploit Issue Tracking Third Party Advisory
https://github.com/libjxl/libjxl/pull/313 Patch Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2021-08-30T20:14:39

Updated: 2021-08-30T20:14:39

Reserved: 2021-07-12T00:00:00


Link: CVE-2021-36692

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2021-08-30T21:15:09.413

Modified: 2021-09-07T20:23:13.163


Link: CVE-2021-36692

JSON object: View

cve-icon Redhat Information

No data.

CWE