OSV-2022-252

Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/grok/OSV-2022-252.yaml
Published
2022-03-18T00:01:35.796630Z
Modified
2022-06-20T00:04:25.180657Z
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=45622

Crash type: Heap-buffer-overflow READ 1
Crash state:
grk::PacketLengthMarkers::readPLM
grk::CodeStreamDecompress::process_marker
grk::CodeStreamDecompress::readHeaderProcedureImpl
References

Affected packages

OSS-Fuzz / grok

grok

Affected ranges

Affected versions

v9.*

v9.7.2
v9.7.3
v9.7.4
v9.7.4.debian
v9.7.5
v9.7.5.debian
v9.7.6
v9.7.7
v9.7.8

Ecosystem specific

{
    "severity": "MEDIUM"
}