Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-19664

Опубликовано: 29 нояб. 2018
Источник: debian

Описание

libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libjpeg-turbonot-affectedpackage

Примечания

  • https://github.com/libjpeg-turbo/libjpeg-turbo/issues/305

  • Introduced in: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/aa7459050d7a50e1d8a99488902d41fbc118a50f

  • Fixed by: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f8cca819a4fb42aafa5f70df43c45e8c416d716f

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 7 лет назад

libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.

CVSS3: 4.3
redhat
около 7 лет назад

libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.

CVSS3: 6.5
nvd
около 7 лет назад

libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.

CVSS3: 6.5
github
больше 3 лет назад

libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg.