VYPR

rpm package

almalinux/turbojpeg

pkg:rpm/almalinux/turbojpeg

Vulnerabilities (4)

  • CVE-2021-29390Aug 22, 2023
    affected < 2.0.90-7.el9fixed 2.0.90-7.el9

    libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.

  • CVE-2021-46822Jun 18, 2022
    affected < 2.0.90-6.el9_1fixed 2.0.90-6.el9_1

    The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in r

  • CVE-2020-17541Jun 1, 2021
    affected < 1.5.3-12.el8fixed 1.5.3-12.el8

    Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

  • CVE-2020-13790Jun 3, 2020
    affected < 1.5.3-14.el8_10fixed 1.5.3-14.el8_10

    libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.