CVE-2024-11403 is a critical out-of-bounds read/write vulnerability affecting LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99, specifically within its JPEG decoder during recompression of untrusted input. This flaw, also present in jpegli, could lead to arbitrary code execution, denial of service, or information disclosure due to uninitialized memory reads or function address overwrites. With a CVSS score of 9.8 (Critical), it is network-exploitable with low attack complexity and no user interaction required, allowing for high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.8.4CPE matchmatch criteria | cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.