« List of all CVEs

CVE-2021-46822

Published: 6/18/2022 Last updated: 8/4/2024 Reserved: 6/18/2022

The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.

CNA assigner: mitre (8254265b-2729-46b6-b9e3-3dfca2d5bfca) Requested by: n/a

Opam packages affected (3)

conf-gd conf-libjpeg grib

Products affected (1)

Product Vendor Version
n/a n/a <= 3.9.16

References (4)