Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-37972

Опубликовано: 21 сент. 2021
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

A flaw was found in the libjpeg-turbo package, where it is susceptible to an out-of-bounds read on crafted input and malformed files. Proper bounds checking is not enforced when processing JPEG files. The highest threat from this vulnerability is system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libjpeg-turboNot affected
Red Hat Enterprise Linux 8libjpeg-turboNot affected
Red Hat Enterprise Linux 9libjpeg-turboNot affected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2006930libjpeg-turbo: Out-of-bounds read in 64-bit SSE2 Huffman encoder

EPSS

Процентиль: 76%
0.01787
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 5 лет назад

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
nvd
почти 5 лет назад

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

msrc
почти 5 лет назад

Chromium: CVE-2021-37972 Out of bounds read in libjpeg-turbo

CVSS3: 8.8
debian
почти 5 лет назад

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.460 ...

CVSS3: 8.8
github
около 4 лет назад

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

EPSS

Процентиль: 76%
0.01787
Низкий

8.8 High

CVSS3