Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2019:2530-1

Опубликовано: 19 нояб. 2019
Источник: suse-cvrf

Описание

Security update for libjpeg-turbo

This update for libjpeg-turbo fixes the following issues:

  • CVE-2019-2201: Several integer overflow issues and subsequent segfaults occurred in libjpeg-turbo, when attempting to compress or decompress gigapixel images. [bsc#1156402]

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.0
libjpeg-turbo-1.5.3-lp150.4.7.1
libjpeg62-62.2.0-lp150.4.7.1
libjpeg62-32bit-62.2.0-lp150.4.7.1
libjpeg62-devel-62.2.0-lp150.4.7.1
libjpeg62-devel-32bit-62.2.0-lp150.4.7.1
libjpeg62-turbo-1.5.3-lp150.4.7.1
libjpeg8-8.1.2-lp150.4.7.1
libjpeg8-32bit-8.1.2-lp150.4.7.1
libjpeg8-devel-8.1.2-lp150.4.7.1
libjpeg8-devel-32bit-8.1.2-lp150.4.7.1
libturbojpeg0-8.1.2-lp150.4.7.1
libturbojpeg0-32bit-8.1.2-lp150.4.7.1

Описание

In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338


Затронутые продукты
openSUSE Leap 15.0:libjpeg-turbo-1.5.3-lp150.4.7.1
openSUSE Leap 15.0:libjpeg62-32bit-62.2.0-lp150.4.7.1
openSUSE Leap 15.0:libjpeg62-62.2.0-lp150.4.7.1
openSUSE Leap 15.0:libjpeg62-devel-32bit-62.2.0-lp150.4.7.1

Ссылки