OSV-2023-546

    Dashboard / Vulnerabilities / OSV-2023-546

    OSV-2023-546

    Published: 6 Jul 2023Last Modified: 6 Jul 2023

    Summary: Invalid-free in jpeg_free_large

    Details: OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=60379 ``` Crash type: Invalid-free Crash state: jpeg_free_large jpeg_abort jpeg_finish_decompress ```

    Affected packages

    Package

    Name: libjpeg-turbo

    Purl: pkg:generic/libjpeg-turbo

    Affected ranges

    Type: GIT

    Events:

    Introduced- 655450bbde5d8a5b63447b8e30256f221a0481c7

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OSV-2023-546 | CVE-DB