Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-17541

Опубликовано: 01 июн. 2021
Источник: debian
EPSS Низкий

Описание

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libjpeg-turbofixed1:2.0.5-1package

Примечания

  • https://github.com/libjpeg-turbo/libjpeg-turbo/commit/c76f4a08263b0cea40d2967560ac7c21f6959079

  • https://github.com/libjpeg-turbo/libjpeg-turbo/issues/392

EPSS

Процентиль: 67%
0.00564
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

CVSS3: 8.8
redhat
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

CVSS3: 8.8
nvd
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

CVSS3: 8.8
msrc
около 4 лет назад

Описание отсутствует

suse-cvrf
около 4 лет назад

Security update for libjpeg-turbo

EPSS

Процентиль: 67%
0.00564
Низкий