libjxl v0.5.0 is affected by a Assertion failed issue in lib/jxl/image.cc jxl::PlaneBase::PlaneBase(). When encoding a malicous GIF file using cjxl, an attacker can trigger a denial of service.
{
"binaries": [
{
"binary_version": "0.7.0-10.2ubuntu6.1",
"binary_name": "libjpegxl-java"
},
{
"binary_version": "0.7.0-10.2ubuntu6.1",
"binary_name": "libjxl-dev"
},
{
"binary_version": "0.7.0-10.2ubuntu6.1",
"binary_name": "libjxl-devtools"
},
{
"binary_version": "0.7.0-10.2ubuntu6.1",
"binary_name": "libjxl-tools"
},
{
"binary_version": "0.7.0-10.2ubuntu6.1",
"binary_name": "libjxl0.7"
}
],
"priority_reason": "This is just a DoS in out of memory conditions"
}
{
"binaries": [
{
"binary_version": "0.11.1-4",
"binary_name": "libjpegxl-java"
},
{
"binary_version": "0.11.1-4",
"binary_name": "libjxl-dev"
},
{
"binary_version": "0.11.1-4",
"binary_name": "libjxl-devtools"
},
{
"binary_version": "0.11.1-4",
"binary_name": "libjxl-gdk-pixbuf"
},
{
"binary_version": "0.11.1-4",
"binary_name": "libjxl-tools"
},
{
"binary_version": "0.11.1-4",
"binary_name": "libjxl0.11"
}
],
"priority_reason": "This is just a DoS in out of memory conditions"
}