Описание
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
libjpeg-turbo | not-affected | package |
Примечания
https://bugzilla.redhat.com/show_bug.cgi?id=1943797
Context: https://github.com/libjpeg-turbo/libjpeg-turbo/pull/724
https://github.com/libjpeg-turbo/libjpeg-turbo/pull/476
Introduced by: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/42825b68d570fb07fe820ac62ad91017e61e9a25 (2.0.90)
Fixed by: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/ccaba5d7894ecfb5a8f11e48d3f86e1f14d5a469 (2.1.0)
EPSS
Связанные уязвимости
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
libjpeg-turbo version 2.0.90 is vulnerable to a heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c.
EPSS