Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2021:4288

Опубликовано: 09 нояб. 2021
Источник: rocky
Оценка: Moderate

Описание

Moderate: libjpeg-turbo security and bug fix update

The libjpeg-turbo packages contain a library of functions for manipulating JPEG images. They also contain simple client programs for accessing the libjpeg functions. These packages provide the same functionality and API as libjpeg but with better performance.

Security Fix(es):

  • libjpeg-turbo: Stack-based buffer overflow in the "transform" component (CVE-2020-17541)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Additional Changes:

For detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
libjpeg-turbox86_6412.el8libjpeg-turbo-1.5.3-12.el8.x86_64.rpm
libjpeg-turbo-develx86_6412.el8libjpeg-turbo-devel-1.5.3-12.el8.x86_64.rpm
libjpeg-turbo-utilsx86_6412.el8libjpeg-turbo-utils-1.5.3-12.el8.x86_64.rpm
turbojpegx86_6412.el8turbojpeg-1.5.3-12.el8.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

CVSS3: 8.8
redhat
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

CVSS3: 8.8
nvd
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

CVSS3: 8.8
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 8.8
debian
около 4 лет назад

Libjpeg-turbo all version have a stack-based buffer overflow in the "t ...