{"id":"CVE-2023-0645","summary":"Out of Bounds read in libjxl","details":"An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159 ","modified":"2026-08-12T03:51:34.370688378Z","published":"2023-04-11T13:22:06.779Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/0xxx/CVE-2023-0645.json","cna_assigner":"Google","cwe_ids":["CWE-125"]},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/06/29/3"},{"type":"WEB","url":"https://github.com/libjxl/libjxl/pull/2101/commits/d95b050c1822a5b1ede9e0dc937e43fca1b10159"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/0xxx/CVE-2023-0645.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-0645"},{"type":"FIX","url":"https://github.com/libjxl/libjxl/pull/2101"},{"type":"PACKAGE","url":"https://github.com/libjxl/libjxl"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libjxl/libjxl","events":[{"introduced":"f95da131cf7c7ccd4da256356fde2fec1fa23bb5"},{"fixed":"c27d499263435ac77007174e0f1cf54557cff23a"}],"database_specific":{"cpe":"cpe:2.3:a:libjxl_project:libjxl:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.7.0"},{"fixed":"0.8.1"},{"introduced":"0"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-0645.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}