Vulnerability Description
The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jpeg-Js Project | Jpeg-Js | < 0.4.4 |
Related Weaknesses (CWE)
References
- https://github.com/jpeg-js/jpeg-js/commit/9ccd35fb5f55a6c4f1902ac5b0f270f675750cPatchThird Party Advisory
- https://github.com/jpeg-js/jpeg-js/issues/105ExploitIssue TrackingThird Party Advisory
- https://github.com/jpeg-js/jpeg-js/pull/106/PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2860295Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JPEGJS-2859218Third Party Advisory
- https://github.com/jpeg-js/jpeg-js/commit/9ccd35fb5f55a6c4f1902ac5b0f270f675750cPatchThird Party Advisory
- https://github.com/jpeg-js/jpeg-js/issues/105ExploitIssue TrackingThird Party Advisory
- https://github.com/jpeg-js/jpeg-js/pull/106/PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2860295Third Party Advisory
- https://snyk.io/vuln/SNYK-JS-JPEGJS-2859218Third Party Advisory
FAQ
What is CVE-2022-25851?
CVE-2022-25851 is a vulnerability with a CVSS score of 7.5 (HIGH). The package jpeg-js before 0.4.4 are vulnerable to Denial of Service (DoS) where a particular piece of input will cause to enter an infinite loop and never return.
How severe is CVE-2022-25851?
CVE-2022-25851 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-25851?
Check the references section above for vendor advisories and patch information. Affected products include: Jpeg-Js Project Jpeg-Js.