Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15232

Опубликовано: 11 окт. 2017
Источник: debian

Описание

libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libjpeg-turbofixed1:2.0.5-1package
libjpeg6bnot-affectedpackage
libjpeg8not-affectedpackage
libjpeg9not-affectedpackage

Примечания

  • https://github.com/libjpeg-turbo/libjpeg-turbo/pull/182

  • https://github.com/mozilla/mozjpeg/issues/268

  • IJG libjpeg releases not affected, see https://lists.debian.org/debian-lts/2017/10/msg00061.html

  • https://github.com/libjpeg-turbo/libjpeg-turbo/commit/073b0e88a192adebbb479ee2456beb089d8b5de7

  • https://github.com/libjpeg-turbo/libjpeg-turbo/commit/5bc43c7821df982f65aa1c738f67fbf7cba8bd69

  • Crash in CLI tools, no security impact

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.

CVSS3: 3.3
redhat
больше 8 лет назад

libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.

CVSS3: 6.5
nvd
больше 8 лет назад

libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.

suse-cvrf
почти 8 лет назад

Security update for libjpeg-turbo

suse-cvrf
больше 8 лет назад

Security update for libjpeg-turbo