CVE-2017-15232NULL Pointer Dereference in Libjpeg-turbo

Severity
6.5MEDIUMNVD
EPSS
0.5%
top 32.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateMar 10

Description

libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

debiandebian/libjpeg-turbo< libjpeg-turbo 1:2.0.5-1 (bookworm)
Debianlibjpeg-turbo/libjpeg-turbo< 1:2.0.5-1+3
debiandebian/libjpeg9< libjpeg-turbo 1:2.0.5-1 (bookworm)
debiandebian/libjpeg6b< libjpeg-turbo 1:2.0.5-1 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xggf-8r3g-7cvj: libjpeg-turbo 12022-05-14
OSV
CVE-2017-15232: libjpeg-turbo 12017-10-11

📋Vendor Advisories

3
Ubuntu
libjpeg-turbo vulnerabilities2018-07-09
Red Hat
libjpeg-turbo: NULL pointer dereference in jdpostct.c and jquant1.c2017-09-30
Debian
CVE-2017-15232: libjpeg-turbo - libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c v...2017

📄Research Papers

1
arXiv
RCABench: Open Benchmarking Platform for Root Cause Analysis2023-03-10

💬Community

4
Bugzilla
CVE-2017-15232 libjpeg-turbo: NULL pointer dereference in jdpostct.c and jquant1.c2017-10-11
Bugzilla
CVE-2017-15232 CVE-2017-9614 libjpeg-turbo: various flaws [fedora-all]2017-07-27
Bugzilla
CVE-2017-15232 CVE-2017-9614 mingw-libjpeg-turbo: various flaws [epel-7]2017-07-27
Bugzilla
CVE-2017-15232 CVE-2017-9614 mingw-libjpeg-turbo: various flaws [fedora-all]2017-07-27
CVE-2017-15232 — NULL Pointer Dereference | cvebase