Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14152

Опубликовано: 11 июн. 2020
Источник: redhat
CVSS3: 7.1

Описание

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

Отчет

Red Hat Enterprise Linux 6 and further versions ships libjpeg-turbo which already contains the fixes, thus these products are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5libjpegOut of support scope
Red Hat Enterprise Linux 6libjpeg-turboNot affected
Red Hat Enterprise Linux 7libjpeg-turboNot affected
Red Hat Enterprise Linux 8libjpeg-turboNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1849026libjpeg: improper handling of max_memory_to_use setting can lead to excessive memory consumption

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
около 6 лет назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

CVSS3: 7.1
nvd
около 6 лет назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

CVSS3: 7.1
msrc
больше 1 года назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

CVSS3: 7.1
debian
около 6 лет назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs. ...

CVSS3: 7.1
github
около 4 лет назад

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

7.1 High

CVSS3

Уязвимость CVE-2020-14152