{"id":"UBUNTU-CVE-2022-38266","details":"An issue in the Leptonica linked library (v1.79.0) allows attackers to cause an arithmetic exception leading to a Denial of Service (DoS) via a crafted JPEG file.","modified":"2026-04-22T15:39:04.099375Z","published":"2022-09-09T22:15:00Z","upstream":["CVE-2022-38266"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-38266"},{"type":"REPORT","url":"https://github.com/tesseract-ocr/tesseract/issues/3498"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-38266"}],"affected":[{"package":{"name":"leptonlib","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/leptonlib@1.70.1-1ubuntu0.1~esm1?arch=source&distro=esm-infra-legacy/trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.69-4ubuntu1","1.69-4ubuntu2","1.69-4ubuntu3","1.69-4ubuntu4","1.70.1-1","1.70.1-1ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"leptonica-progs","binary_version":"1.70.1-1ubuntu0.1~esm1"},{"binary_name":"liblept4","binary_version":"1.70.1-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-38266.json"}},{"package":{"name":"tesseract","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/tesseract@3.03.02-3?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.02.02-1","3.03.02-3"],"ecosystem_specific":{"binaries":[{"binary_name":"libtesseract3","binary_version":"3.03.02-3"},{"binary_name":"tesseract-ocr","binary_version":"3.03.02-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-38266.json"}},{"package":{"name":"leptonlib","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/leptonlib@1.73-1ubuntu0.1~esm1?arch=source&distro=esm-apps/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.72-3","1.72-3build1","1.73-1","1.73-1ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"leptonica-progs","binary_version":"1.73-1ubuntu0.1~esm1"},{"binary_name":"liblept5","binary_version":"1.73-1ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-38266.json"}},{"package":{"name":"tesseract","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/tesseract@3.04.01-4?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.04.00-5ubuntu1","3.04.01-2","3.04.01-4"],"ecosystem_specific":{"binaries":[{"binary_name":"libtesseract3","binary_version":"3.04.01-4"},{"binary_name":"tesseract-ocr","binary_version":"3.04.01-4"},{"binary_name":"tesseract-ocr-all","binary_version":"3.04.01-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-38266.json"}},{"package":{"name":"leptonlib","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/leptonlib@1.75.3-3ubuntu0.1~esm1?arch=source&distro=esm-apps/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.74.4-1","1.74.4-2","1.75.3-1","1.75.3-2","1.75.3-3","1.75.3-3ubuntu0.1~esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"leptonica-progs","binary_version":"1.75.3-3ubuntu0.1~esm1"},{"binary_name":"liblept5","binary_version":"1.75.3-3ubuntu0.1~esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-38266.json"}},{"package":{"name":"tesseract","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/tesseract@4.00~git2288-10f4998a-2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.04.01-6","3.04.01-6build1","3.04.01-6build2","4.00~git2188-cdc35338-4build1","4.00~git2188-cdc35338-5","4.00~git2207-766b7bd6-3.1","4.00~git2219-40f43111-1.2","4.00~git2288-10f4998a-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libtesseract4","binary_version":"4.00~git2288-10f4998a-2"},{"binary_name":"tesseract-ocr","binary_version":"4.00~git2288-10f4998a-2"},{"binary_version":"4.00~git2288-10f4998a-2","binary_name":"tesseract-ocr-all"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-38266.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}