Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-17541

Опубликовано: 01 июн. 2021
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

A stack-based buffer overflow flaw was found in libjpeg-turbo library in the tranform component. An attacker may use this flaw to input a malicious image file to an application utilizing this library, leading to arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libjpeg-turboOut of support scope
Red Hat Enterprise Linux 7libjpeg-turboOut of support scope
Red Hat Enterprise Linux 8mingw-libjpeg-turboAffected
Red Hat Enterprise Linux 9libjpeg-turboNot affected
Red Hat Enterprise Linux 8libjpeg-turboFixedRHSA-2021:428809.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1968036libjpeg-turbo: Stack-based buffer overflow in the "transform" component

EPSS

Процентиль: 67%
0.00564
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

CVSS3: 8.8
nvd
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

CVSS3: 8.8
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 8.8
debian
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "t ...

suse-cvrf
около 4 лет назад

Security update for libjpeg-turbo

EPSS

Процентиль: 67%
0.00564
Низкий

8.8 High

CVSS3