CVE-2014-9092
published 2017-10-10CVE-2014-9092: libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
PriorityP426medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
3.23%
86.9th percentile
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libjpeg-turbo | < libjpeg-turbo 1:1.3.1-11 (bookworm) | libjpeg-turbo 1:1.3.1-11 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libjpeg-turbo | libjpeg-turbo | <= 1.2.90 | — |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:1.3.1-11 | 1:1.3.1-11 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:1.3.1-11 | 1:1.3.1-11 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:1.3.1-11 | 1:1.3.1-11 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:1.3.1-11 | 1:1.3.1-11 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2018-07-10
CVE-2014-9092 libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: libjpeg-turbo could be made to crash or run programs as your login if it
opened a specially crafted file.
USN-3706-1 fixed a vulnerability in libjpeg-turbo. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libjpeg-turbo incorrectly handled certain malformed
JPEG images. If a user or automated system were tricked into opening a
specially crafted JPEG image, a remote attacker could cause libjpeg-turbo
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2018-07-09
CVE-2014-9092 libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: libjpeg-turbo could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that libjpeg-turbo incorrectly handled certain malformed
JPEG images. If a user or automated system were tricked into opening a
specially crafted JPEG image, a remote attacker could cause libjpeg-turbo
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libjpeg-turbo: denial of service via specially-crafted JPEG file
vendor_redhat·2014-10-26·CVSS 6.5
CVE-2014-9092 [MEDIUM] libjpeg-turbo: denial of service via specially-crafted JPEG file
libjpeg-turbo: denial of service via specially-crafted JPEG file
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
Package: libjpeg-turbo (Red Hat Enterprise Linux 6) - Will not fix
Package: libjpeg-turbo (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2014-9092: libjpeg-turbo - libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service ...
vendor_debian·2014·CVSS 6.5
CVE-2014-9092 [MEDIUM] CVE-2014-9092: libjpeg-turbo - libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service ...
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
Scope: local
bookworm: resolved (fixed in 1:1.3.1-11)
bullseye: resolved (fixed in 1:1.3.1-11)
forky: resolved (fixed in 1:1.3.1-11)
sid: resolved (fixed in 1:1.3.1-11)
trixie: resolved (fixed in 1:1.3.1-11)
GHSA
GHSA-c37w-643x-858q: libjpeg-turbo before 1
ghsa_unreviewed·2022-05-14
CVE-2014-9092 [MEDIUM] CWE-119 GHSA-c37w-643x-858q: libjpeg-turbo before 1
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
OSV
CVE-2014-9092: libjpeg-turbo before 1
osv·2017-10-10·CVSS 6.5
CVE-2014-9092 [MEDIUM] CVE-2014-9092: libjpeg-turbo before 1
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file
bugzilla·2014-12-02·CVSS 6.5
CVE-2014-9092 [MEDIUM] CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file
CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file
A flaw in libjpeg-turbo was reported [1],[2],[3] that could lead to a local denial of service when processing a specially-crafted JPEG issue.
One of the reports indicate that this only affects versions of libjpeg-turbo prior to 1.3.1 due to 1.3.1 rejecting the malformed image due to duplicate SOI markers.
Upstream has fixes for this issue [4],[5]. Also refer to the upstream bug [6].
[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26482&sid=81658bc2f51a8d9893279cd01e83783f
[2] http://seclists.org/oss-sec/2014/q4/557
[3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=768369
[4] http://sourceforge.net/p/libjpeg-turbo/code/1365/
[5] http://sourceforge.net/p/libjpeg-turbo/code/1367/
[6] htt
Bugzilla
CVE-2014-9092 mingw-libjpeg-turbo: libjpeg-turbo: denial of service via specially-crafted JPEG file [epel-7]
bugzilla·2014-12-02·CVSS 6.5
CVE-2014-9092 [MEDIUM] CVE-2014-9092 mingw-libjpeg-turbo: libjpeg-turbo: denial of service via specially-crafted JPEG file [epel-7]
CVE-2014-9092 mingw-libjpeg-turbo: libjpeg-turbo: denial of service via specially-crafted JPEG file [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
epel-7 tracking bug
Bugzilla
CVE-2014-9092 mingw-libjpeg-turbo: libjpeg-turbo: denial of service via specially-crafted JPEG file [fedora-all]
bugzilla·2014-12-02·CVSS 6.5
CVE-2014-9092 [MEDIUM] CVE-2014-9092 mingw-libjpeg-turbo: libjpeg-turbo: denial of service via specially-crafted JPEG file [fedora-all]
CVE-2014-9092 mingw-libjpeg-turbo: libjpeg-turbo: denial of service via specially-crafted JPEG file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file [fedora-all]
bugzilla·2014-12-02·CVSS 6.5
CVE-2014-9092 [MEDIUM] CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file [fedora-all]
CVE-2014-9092 libjpeg-turbo: denial of service via specially-crafted JPEG file [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supporte
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147315.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147336.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150957.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150967.htmlhttp://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26482&sid=81658bc2f51a8d9893279cd01e83783fhttp://www.openwall.com/lists/oss-security/2014/11/26/8http://www.securityfocus.com/bid/71326https://bugzilla.redhat.com/show_bug.cgi?id=1169845https://tapani.tarvainen.info/linux/convertbug/https://usn.ubuntu.com/3706-1/https://usn.ubuntu.com/3706-2/http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147315.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-January/147336.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150957.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-March/150967.htmlhttp://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26482&sid=81658bc2f51a8d9893279cd01e83783fhttp://www.openwall.com/lists/oss-security/2014/11/26/8http://www.securityfocus.com/bid/71326https://bugzilla.redhat.com/show_bug.cgi?id=1169845https://tapani.tarvainen.info/linux/convertbug/https://usn.ubuntu.com/3706-1/https://usn.ubuntu.com/3706-2/
2017-10-10
Published