Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-37972

Опубликовано: 21 сент. 2021
Источник: redhat
CVSS3: 8.8

Описание

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

A flaw was found in the libjpeg-turbo package, where it is susceptible to an out-of-bounds read on crafted input and malformed files. Proper bounds checking is not enforced when processing JPEG files. The highest threat from this vulnerability is system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7libjpeg-turboNot affected
Red Hat Enterprise Linux 8libjpeg-turboNot affected
Red Hat Enterprise Linux 9libjpeg-turboNot affected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2006930libjpeg-turbo: Out-of-bounds read in 64-bit SSE2 Huffman encoder

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 4 лет назад

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVSS3: 8.8
nvd
больше 4 лет назад

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

msrc
больше 4 лет назад

Chromium: CVE-2021-37972 Out of bounds read in libjpeg-turbo

CVSS3: 8.8
debian
больше 4 лет назад

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.460 ...

CVSS3: 8.8
github
больше 3 лет назад

Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

8.8 High

CVSS3