VDB
CVE-2022-38266
CVE-2022-38266
PUBLISHED
CVSS 6.5 MEDIUM
An issue in the Leptonica linked library (v1.79.0) in Tesseract v5.0.0 allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.
EPSS 0.31% · 54.3th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
0.31%
54.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| tesseract_project | tesseract | 5.0.0 |
| leptonica | leptonica | 0 |
| debian | debian_linux | 10.0 |
Timeline
- Sep 9, 2022 CVE Published
- Sep 10, 2022 EPSS Score
- Oct 25, 2022 EPSS Score
- Dec 9, 2022 EPSS Score
- Jan 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 9, 2023 EPSS Score
- Apr 24, 2023 EPSS Score
- Jun 8, 2023 EPSS Score
- Jul 23, 2023 EPSS Score
- Sep 6, 2023 EPSS Score
- Oct 21, 2023 EPSS Score
References
- https://github.com/tesseract-ocr/tesseract/issues/3498 url
- https://github.com/DanBloomberg/leptonica/commit/f062b42c0ea8dddebdc6a152fd16152de215d614 url
- [debian-lts-announce] 20221208 [SECURITY] [DLA 3233-1] leptonlib security update mailing-list
- GLSA-202312-01 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-38266 advisory