
Cloud Vulnerability DB
A community-led vulnerabilities database
In libjpeg version 1.63, a NULL pointer dereference vulnerability was identified in the LineBuffer::FetchRegion function within linebuffer.cpp. The vulnerability was assigned CVE-2022-32202 and was disclosed on June 2, 2022 (CVE Details, Debian Tracker).
The vulnerability occurs in the line-based reconstruction process when no valid scan is found and no data is present. The issue specifically manifests in the LineBuffer::FetchRegion function where a NULL pointer dereference can occur during image processing (GitHub Commit). The vulnerability requires local access and user interaction to be exploited (AttackerKB).
When exploited, this vulnerability can lead to a program crash due to the NULL pointer dereference, potentially causing a denial of service condition in applications using the affected libjpeg library (Debian Tracker).
The vulnerability has been fixed in later versions of libjpeg. The fix involves adding a NULL pointer check before accessing the image data in the LineBuffer::FetchRegion function. Users are advised to upgrade to a patched version. For Debian systems, fixed versions are available in bookworm (0.0~git20220805.54ec643-1) and later releases (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."