VYPR

rpm package

suse/libjpeg62-turbo&distro=SUSE Linux Enterprise Software Development Kit 12 SP3

pkg:rpm/suse/libjpeg62-turbo&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3

Vulnerabilities (4)

  • CVE-2018-14498Mar 7, 2019
    affected < 1.5.3-31.14.2fixed 1.5.3-31.14.2

    get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of

  • CVE-2018-1152MedJun 18, 2018
    affected < 1.5.3-31.14.2fixed 1.5.3-31.14.2

    libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.

  • CVE-2018-11813HigJun 6, 2018
    affected < 1.5.3-31.14.2fixed 1.5.3-31.14.2

    libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

  • CVE-2017-15232MedOct 11, 2017
    affected < 1.5.3-31.7.4fixed 1.5.3-31.7.4

    libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.