Описание
Security update for libjpeg-turbo
This update for libjpeg-turbo fixes the following issues:
- CVE-2019-2201: Several integer overflow issues and subsequent segfaults occurred in libjpeg-turbo, when attempting to compress or decompress gigapixel images. [bsc#1156402]
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.1
libjpeg-turbo-1.5.3-lp151.6.3.1
libjpeg62-62.2.0-lp151.6.3.1
libjpeg62-32bit-62.2.0-lp151.6.3.1
libjpeg62-devel-62.2.0-lp151.6.3.1
libjpeg62-devel-32bit-62.2.0-lp151.6.3.1
libjpeg62-turbo-1.5.3-lp151.6.3.1
libjpeg8-8.1.2-lp151.6.3.1
libjpeg8-32bit-8.1.2-lp151.6.3.1
libjpeg8-devel-8.1.2-lp151.6.3.1
libjpeg8-devel-32bit-8.1.2-lp151.6.3.1
libturbojpeg0-8.1.2-lp151.6.3.1
libturbojpeg0-32bit-8.1.2-lp151.6.3.1
Ссылки
- E-Mail link for openSUSE-SU-2019:2529-1
- SUSE Security Ratings
- SUSE Bug 1156402
- SUSE CVE CVE-2019-2201 page
Описание
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338
Затронутые продукты
openSUSE Leap 15.1:libjpeg-turbo-1.5.3-lp151.6.3.1
openSUSE Leap 15.1:libjpeg62-32bit-62.2.0-lp151.6.3.1
openSUSE Leap 15.1:libjpeg62-62.2.0-lp151.6.3.1
openSUSE Leap 15.1:libjpeg62-devel-32bit-62.2.0-lp151.6.3.1
Ссылки
- CVE-2019-2201
- SUSE Bug 1156402