Vulnerabilities > CVE-2021-36692 - Divide By Zero vulnerability in Libjxl Project Libjxl 0.3.7

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
libjxl-project
CWE-369

Summary

libjxl v0.3.7 is affected by a Divide By Zero in issue in lib/extras/codec_apng.cc jxl::DecodeImageAPNG(). When encoding a malicous APNG file using cjxl, an attacker can trigger a denial of service.

Vulnerable Configurations

Part Description Count
Application
Libjxl_Project
1

Common Weakness Enumeration (CWE)