VDB
Sign up
HIGH7.5

GHSA-xvf7-4v9q-58w6

Infinite loop in jpeg-js

Quick fix

GHSA-xvf7-4v9q-58w6 — jpeg-js: upgrade to the fixed version with the command below.

npm install jpeg-js@0.4.4

Details

The package jpeg-js before 0.4.4 is vulnerable to Denial of Service (DoS) where a particular piece of input will cause the program to enter an infinite loop and never return.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jpeg-js
Introduced in: 0Fixed in: 0.4.4
Fixnpm install jpeg-js@0.4.4

References