Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20330

Опубликовано: 25 нояб. 2018
Источник: redhat
CVSS3: 4.3

Описание

The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.

Отчет

This issue did not affect the versions of libjpeg-turbo as shipped with Red Hat Enterprise Linux 6 and 7.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libjpeg-turboNot affected
Red Hat Enterprise Linux 7libjpeg-turboNot affected
Red Hat Enterprise Linux 8libjpeg-turboNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-190->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1665223libjpeg-turbo: heap-based buffer overflow in tjLoadImage

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.

CVSS3: 8.8
nvd
около 7 лет назад

The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.

CVSS3: 8.8
debian
около 7 лет назад

The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflo ...

CVSS3: 8.8
github
больше 3 лет назад

The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.

4.3 Medium

CVSS3