Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14152

Опубликовано: 11 июн. 2020
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

Отчет

Red Hat Enterprise Linux 6 and further versions ships libjpeg-turbo which already contains the fixes, thus these products are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libjpegOut of support scope
Red Hat Enterprise Linux 6libjpeg-turboNot affected
Red Hat Enterprise Linux 7libjpeg-turboNot affected
Red Hat Enterprise Linux 8libjpeg-turboNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1849026libjpeg: improper handling of max_memory_to_use setting can lead to excessive memory consumption

EPSS

Процентиль: 76%
0.00981
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 5 лет назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

CVSS3: 7.1
nvd
больше 5 лет назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

CVSS3: 7.1
msrc
11 месяцев назад

Описание отсутствует

CVSS3: 7.1
debian
больше 5 лет назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs. ...

CVSS3: 7.1
github
больше 3 лет назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

EPSS

Процентиль: 76%
0.00981
Низкий

7.1 High

CVSS3