Описание
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
A heap buffer over-read flaw was found in libjpeg-turbo. For certain types of smoothed jpeg images, the decompress_smooth_data() function may improperly enter a condition statement that leads to heap memory read of uninitialized data, which may cause an application crash or loss of confidentiality.
Отчет
The amount of memory read is very small and not controllable by an attacker, which lowers the impact of this flaw to Moderate.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 6 | libjpeg-turbo | Out of support scope | ||
Red Hat Enterprise Linux 7 | libjpeg-turbo | Out of support scope | ||
Red Hat Enterprise Linux 8 | libjpeg-turbo | Not affected | ||
Red Hat Enterprise Linux 9 | libjpeg-turbo | Fixed | RHSA-2024:2295 | 30.04.2024 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.1 High
CVSS3
Связанные уязвимости
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 byte ...
libjpeg-turbo version 2.0.90 is vulnerable to a heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c.
EPSS
7.1 High
CVSS3