JPEG XL (aka jpeg-xl) through 0.3.2 allows writable memory corruption.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://gitlab.com/wg1/jpeg-xl/-/tags | third party advisory |
http://www.openwall.com/lists/oss-security/2021/03/01/3 | third party advisory mailing list |
http://seclists.org/fulldisclosure/2021/Mar/2 | third party advisory mailing list |
http://packetstormsecurity.com/files/161623/jpeg-xl-0.3.1-Memory-Corruption.html | third party advisory |