Vulnerabilities > CVE-2021-28026 - Out-of-bounds Write vulnerability in Jpeg Jpeg-Xl 0.3.2
Attack vector
LOCAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
jpeg-xl v0.3.2 is affected by a heap buffer overflow in /lib/jxl/coeff_order.cc ReadPermutation. When decoding a malicous jxl file using djxl, an attacker can trigger arbitrary code execution or a denial of service.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |