Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2019-3705

Опубликовано: 14 нояб. 2019
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2019-3705: libjpeg-turbo security update (MODERATE)

[1.5.3-10]

  • Fix CVE-2018-14498 (#1687477)

[1.5.3-9]

  • Fix LDFLAGS (#1688397)

[1.5.3-8]

  • Support running with Intel CET (#1688397)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libjpeg-turbo

1.5.3-10.el8

libjpeg-turbo-devel

1.5.3-10.el8

libjpeg-turbo-utils

1.5.3-10.el8

turbojpeg

1.5.3-10.el8

turbojpeg-devel

1.5.3-10.el8

Oracle Linux x86_64

libjpeg-turbo

1.5.3-10.el8

libjpeg-turbo-devel

1.5.3-10.el8

libjpeg-turbo-utils

1.5.3-10.el8

turbojpeg

1.5.3-10.el8

turbojpeg-devel

1.5.3-10.el8

Связанные CVE

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

CVSS3: 4.4
redhat
больше 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

CVSS3: 6.5
nvd
почти 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.

CVSS3: 6.5
debian
почти 7 лет назад

get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG th ...

rocky
больше 6 лет назад

Moderate: libjpeg-turbo security update