rpm package
almalinux/turbojpeg-devel
pkg:rpm/almalinux/turbojpeg-devel
Vulnerabilities (5)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2021-29390 | — | < 2.0.90-7.el9 | 2.0.90-7.el9 | Aug 22, 2023 | libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c. | ||
| CVE-2021-46822 | — | < 2.0.90-6.el9_1 | 2.0.90-6.el9_1 | Jun 18, 2022 | The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in r | ||
| CVE-2020-17541 | — | < 1.5.3-12.el8 | 1.5.3-12.el8 | Jun 1, 2021 | Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service. | ||
| CVE-2020-13790 | — | < 1.5.3-14.el8_10 | 1.5.3-14.el8_10 | Jun 3, 2020 | libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file. | ||
| CVE-2018-14498 | — | < 1.5.3-10.el8 | 1.5.3-10.el8 | Mar 7, 2019 | get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of |
- CVE-2021-29390Aug 22, 2023affected < 2.0.90-7.el9fixed 2.0.90-7.el9
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
- CVE-2021-46822Jun 18, 2022affected < 2.0.90-6.el9_1fixed 2.0.90-6.el9_1
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in r
- CVE-2020-17541Jun 1, 2021affected < 1.5.3-12.el8fixed 1.5.3-12.el8
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
- CVE-2020-13790Jun 3, 2020affected < 1.5.3-14.el8_10fixed 1.5.3-14.el8_10
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
- CVE-2018-14498Mar 7, 2019affected < 1.5.3-10.el8fixed 1.5.3-10.el8
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of