Описание
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
A divide by zero vulnerability has been discovered in libjpeg-turbo in alloc_sarray function of jmemmgr.c file. An attacker could use this vulnerability to cause a denial of service via a crafted file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | libjpeg | Will not fix | ||
| Red Hat Enterprise Linux 6 | libjpeg-turbo | Will not fix | ||
| Red Hat Enterprise Linux 8 | libjpeg-turbo | Not affected | ||
| Red Hat Enterprise Linux 6 Supplementary | java-1.8.0-ibm | Fixed | RHSA-2019:0469 | 06.03.2019 |
| Red Hat Enterprise Linux 6 Supplementary | java-1.7.1-ibm | Fixed | RHSA-2019:0474 | 07.03.2019 |
| Red Hat Enterprise Linux 7 | libjpeg-turbo | Fixed | RHSA-2019:2052 | 06.08.2019 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.8.0-ibm | Fixed | RHSA-2019:0472 | 08.03.2019 |
| Red Hat Enterprise Linux 7 Supplementary | java-1.7.1-ibm | Fixed | RHSA-2019:0473 | 08.03.2019 |
| Red Hat Enterprise Linux 8 | java-1.8.0-ibm | Fixed | RHSA-2019:1238 | 16.05.2019 |
| Red Hat Satellite 5.8 | java-1.8.0-ibm | Fixed | RHSA-2019:0640 | 25.03.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray functio ...
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
Уязвимость компонента ImageIO (libjpeg) программных платформ Oracle Java SE, Java SE Embedded, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
6.5 Medium
CVSS3