An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
Medium CVSS 6.5
Summary
An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/DanBloomberg/leptonica/commit/f062b42c0ea8dddebdc6a152fd16152de215d614 Patch
- https://github.com/tesseract-ocr/tesseract/issues/3498 Exploit
- https://lists.debian.org/debian-lts-announce/2022/12/msg00018.html Mailing List
- https://security.gentoo.org/glsa/202312-01
- https://github.com/DanBloomberg/leptonica/commit/f062b42c0ea8dddebdc6a152fd16152de215d614 Patch
- https://github.com/tesseract-ocr/tesseract/issues/3498 Exploit
- https://lists.debian.org/debian-lts-announce/2022/12/msg00018.html Mailing List
- https://security.gentoo.org/glsa/202312-01
Timeline
- nvd_ingest NVD