Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-2201

Опубликовано: 05 июл. 2019
Источник: redhat
CVSS3: 7.8

Описание

In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338

A vulnerability was found in libjpeg-turbo that could allow a remote attacker to execute arbitrary code on the system, which is caused by an integer overflow, which leads to subsequent heap corruption.

Отчет

This vulnerability is rated as a moderate, due to a missing bounds check  in generate_jsimd_ycc_rgb_convert_neon within jsimd_arm64_neon.S, which could cause an out-of-bounds write, this could result in remote code execution, it requires user interaction (such as opening a crafted file) for exploitation, achieving successful exploitation is difficult and depends on specific conditions.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libjpeg-turboOut of support scope
Red Hat Enterprise Linux 7libjpeg-turboWill not fix
Red Hat Enterprise Linux 8libjpeg-turboWill not fix
Red Hat Enterprise Linux 8mingw-libjpeg-turboWill not fix
Red Hat Enterprise Linux 9libjpeg-turboNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1770982libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 7 лет назад

In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338

CVSS3: 7.8
nvd
почти 7 лет назад

In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338

CVSS3: 7.8
debian
почти 7 лет назад

In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is ...

suse-cvrf
почти 7 лет назад

Security update for libjpeg-turbo

suse-cvrf
почти 7 лет назад

Security update for libjpeg-turbo

7.8 High

CVSS3