HIGH
stb: integer shift of invalid size in stbi__jpeg_decode_block_prog_ac()
Published Apr 15, 2022
8.8
HIGHCVSS 3.1
EPSS 1.58%
Description
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
Affected products
No data.
Configuration 1
- 2.27
Configuration 2
OR
- 34
- 35
- 36
No data.
Red Hat Enterprise Linux 6
clutter
Out of support scope
Red Hat Enterprise Linux 7
cogl
Not affected
Red Hat Enterprise Linux 7
compat-cogl114
Not affected
Red Hat Enterprise Linux 8
cogl
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | clutter | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | cogl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | compat-cogl114 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | cogl | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw does not affect the versions of cogl shipped with Red Hat Enterprise Linux 7 or 8 because the affected code is not shipped in those packages. This flaw is out of support scope for Red Hat Enterprise Linux 6.
Weaknesses (2)
References (10)
- https://access.redhat.com/security/cve/CVE-2022-28048 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2077028 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-32534 Advisory
- https://github.com/nothings/stb/issues/1293 x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://github.com/nothings/stb/pull/1297 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5FXLM5XL77SNH4IPTSXOQD7XL4E2EMIN/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I4HXIWU5HBOADXZVMREHT4YTO5WVYXEQ/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MMBCMJGAZRQS55SNECUWZSC5URVLEZ5R/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2022-28048
- https://www.cve.org/CVERecord?id=CVE-2022-28048
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 15, 2022
Updated Aug 3, 2024
Reserved Mar 28, 2022
Link CVE-2022-28048
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-32534 Assigner mitre
Published Apr 15, 2022
Updated Aug 3, 2024
Exploited since n/a
Link EUVD-2022-32534