CVE-2022-31796 describes a heap-based buffer over-read vulnerability in libjpeg version 1.63, specifically within the HierarchicalBitmapRequester::FetchRegion function, due to a mismatch in MCU size during allocation and use. This flaw carries a CVSS score of 6.5 (Medium), indicating a network-based attack with low complexity, requiring user interaction, and potentially leading to high availability impact. While no active exploitation, public exploit code, or significant community discussion has been observed, organizations utilizing affected versions of libjpeg should consider patching to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.63CPE matchmatch criteria | cpe:2.3:a:jpeg:libjpeg:1.63:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.