JPX Fragment List (flst) box vulnerability in Kakadu 7.9 allows an attacker to exfiltrate local and remote files reachable by a server if the server allows the attacker to upload a specially-crafted the image that is displayed back to the attacker.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Google

Published: 2023-12-20T13:11:39.208Z

Updated: 2024-08-02T08:35:14.693Z

Reserved: 2023-12-06T17:20:19.819Z

Link: CVE-2023-6562

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-20T13:15:07.260

Modified: 2023-12-28T20:00:23.110

Link: CVE-2023-6562

cve-icon Redhat

No data.