Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-7540

Опубликовано: 15 мая 2025
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2025-7540: libjpeg-turbo security update (MODERATE)

[1.5.3-14]

  • updated previous fix (RHEL-87364)

[1.5.3-13]

  • fix CVE-2020-13790: heap-based buffer over-read in get_rgb_row (RHEL-87364)

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

libjpeg-turbo

1.5.3-14.el8_10

libjpeg-turbo-devel

1.5.3-14.el8_10

libjpeg-turbo-utils

1.5.3-14.el8_10

turbojpeg

1.5.3-14.el8_10

turbojpeg-devel

1.5.3-14.el8_10

Oracle Linux x86_64

libjpeg-turbo

1.5.3-14.el8_10

libjpeg-turbo-devel

1.5.3-14.el8_10

libjpeg-turbo-utils

1.5.3-14.el8_10

turbojpeg

1.5.3-14.el8_10

turbojpeg-devel

1.5.3-14.el8_10

Связанные CVE

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 5 лет назад

libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.

CVSS3: 8.1
redhat
около 5 лет назад

libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.

CVSS3: 8.1
nvd
около 5 лет назад

libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.

CVSS3: 8.1
debian
около 5 лет назад

libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-r ...

suse-cvrf
почти 5 лет назад

Security update for libjpeg-turbo