CVE-2019-2201
published 2019-11-13CVE-2019-2201: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote…
PriorityP344high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.46%
82.6th percentile
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | libjpeg-turbo | < libjpeg-turbo 1:2.0.5-1 (bookworm) | libjpeg-turbo 1:2.0.5-1 (bookworm) |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.4.2-0ubuntu3.3 | 1.4.2-0ubuntu3.3 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.5.2-0ubuntu5.18.04.3 | 1.5.2-0ubuntu5.18.04.3 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2019-11-13·CVSS 6.5
CVE-2018-14498 [MEDIUM] libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: Several security issues were fixed in libjpeg-turbo.
It was discovered that libjpeg-turbo incorrectly handled certain BMP images.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-14498)
It was discovered that libjpeg-turbo incorrectly handled certain JPEG images.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 19.04. (CVE-2018-19664)
It was discovered that libjpeg-turbo incorrectly handled certain BMP images.
An attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 19.04. (CVE-2018-20330)
It was discovered that libjpeg-turbo incorrectly han
Android
CVE-2019-2201: Android Security Bulletin 2019-11-01
CVE: CVE-2019-2201
Severity: HIGH
Type: RCE
Affected AOSP versions: 8
vendor_android·2019-11-01·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201: Android Security Bulletin 2019-11-01
CVE: CVE-2019-2201
Severity: HIGH
Type: RCE
Affected AOSP versions: 8
Android Security Bulletin 2019-11-01
CVE: CVE-2019-2201
Severity: HIGH
Type: RCE
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-120551338
Red Hat
libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images
vendor_redhat·2019-07-05·CVSS 7.8
CVE-2019-2201 [HIGH] CWE-190 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images
libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338
A vulnerability was found in libjpeg-turbo that could allow a remote attacker to execute arbitrary code on the system, which is caused by an integer overflow, which leads to subsequent heap corruption.
Statement: This vulnerability is rated as a moderate, due to a missing bounds check in
Debian
CVE-2019-2201: libjpeg-turbo - In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possibl...
vendor_debian·2019·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201: libjpeg-turbo - In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possibl...
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye: resolved (fixed in 1:2.0.5-1)
forky: resolved (fixed in 1:2.0.5-1)
sid: resolved (fixed in 1:2.0.5-1)
trixie: resolved (fixed in 1:2.0.5-1)
GHSA
GHSA-x9wg-q72x-x5w7: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon
ghsa_unreviewed·2022-05-24
CVE-2019-2201 [HIGH] CWE-787 GHSA-x9wg-q72x-x5w7: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338
OSV
CVE-2019-2201: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon
osv·2019-11-13·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201: In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-120551338
OSV
libjpeg-turbo vulnerabilities
osv·2019-11-13·CVSS 6.5
CVE-2018-14498 [MEDIUM] libjpeg-turbo vulnerabilities
libjpeg-turbo vulnerabilities
It was discovered that libjpeg-turbo incorrectly handled certain BMP images.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS.
(CVE-2018-14498)
It was discovered that libjpeg-turbo incorrectly handled certain JPEG images.
An attacker could possibly use this issue to expose sensitive information.
This issue only affected Ubuntu 19.04. (CVE-2018-19664)
It was discovered that libjpeg-turbo incorrectly handled certain BMP images.
An attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 19.04. (CVE-2018-20330)
It was discovered that libjpeg-turbo incorrectly handled certain JPEG images.
An attacker could possibly cause a denial of
No detection rules found.
No public exploits indexed.
Bugzilla
libjpeg-turbo: out-of-bounds write in tjDecompressToYUV2() and tjDecompressToYUVPlanes()
bugzilla·2020-06-24·CVSS 7.8
[HIGH] libjpeg-turbo: out-of-bounds write in tjDecompressToYUV2() and tjDecompressToYUVPlanes()
libjpeg-turbo: out-of-bounds write in tjDecompressToYUV2() and tjDecompressToYUVPlanes()
A vulnerability was found in libjpeg-turbo, where a fixed out-of-bounds write in tjDecompressToYUV2() and tjDecompressToYUVPlanes() (sometimes manifesting as a double free) that occurred when attempting to decompress grayscale JPEG images that were compressed with a sampling factor other than 1.
References:
https://bugs.gentoo.org/727910
Discussion:
Created libjpeg-turbo tracking bugs for this issue:
Affects: fedora-all [bug 1850485]
---
This is same as CVE-2019-2201
---
*** This bug has been marked as a duplicate of bug 1770982 ***
---
Upstream bug: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/387
Upstream commit at: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/dab6be4cfb2
Bugzilla
libjpeg-turbo: decompression of images greater than 715827882 pixels causing integer overflow
bugzilla·2020-06-24·CVSS 7.8
[HIGH] libjpeg-turbo: decompression of images greater than 715827882 pixels causing integer overflow
libjpeg-turbo: decompression of images greater than 715827882 pixels causing integer overflow
A vulnerability was found in libjpeg-turbo, where a fixed signed integer overflow and subsequent segfault that occurred when attempting to decompress images with more than 715827882 pixels using the 64-bit C version of TJBench.
References:
https://bugs.gentoo.org/727910
Discussion:
Created libjpeg-turbo tracking bugs for this issue:
Affects: fedora-all [bug 1850478]
---
*** Bug 1850474 has been marked as a duplicate of this bug. ***
---
Upstream bug: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/388
Upstream commit: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/c30b1e72dac76343ef9029833d1561de07d29bada
---
This bug represents the second part of the fix committed for CVE-
Bugzilla
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
bugzilla·2019-11-11·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM ch
Bugzilla
CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images
bugzilla·2019-11-11·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images
CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images
Several integer overflow issues and subsequent segfaults occur in libjpeg-turbo when attempting to compress or decompress gigapixel images.
Reference:
https://github.com/libjpeg-turbo/libjpeg-turbo/issues/361
Upstream commit:
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/2a9e3bd7430cfda1bc812d139e0609c6aca0b884
Discussion:
Created libjpeg-turbo tracking bugs for this issue:
Affects: fedora-all [bug 1770988]
Created mingw-libjpeg-turbo tracking bugs for this issue:
Affects: epel-7 [bug 1770990]
Affects: fedora-all [bug 1770989]
---
The initial commit done by upstream at https://github.com/libjpeg-turbo/libjpeg-turbo/commit/2a9e3bd7430cfda
Bugzilla
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [epel-7]
bugzilla·2019-11-11·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [epel-7]
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog
Bugzilla
CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
bugzilla·2019-11-11·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
Bugzilla
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
bugzilla·2019-11-11·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM ch
Bugzilla
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [epel-7]
bugzilla·2019-11-11·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [epel-7]
CVE-2019-2201 mingw-libjpeg-turbo: libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog
Bugzilla
CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
bugzilla·2019-11-11·CVSS 7.8
CVE-2019-2201 [HIGH] CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
CVE-2019-2201 libjpeg-turbo: several integer overflows and subsequent segfaults when attempting to compress/decompress gigapixel images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpk
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00048.htmlhttps://lists.apache.org/thread.html/rc800763a88775ac9abb83b3402bcd0913d41ac65fdfc759af38f2280%40%3Ccommits.mxnet.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2022/05/msg00048.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4QPASQPZO644STRFTLOD35RIRGWWRNI/https://security.gentoo.org/glsa/202003-23https://source.android.com/security/bulletin/2019-11-01https://usn.ubuntu.com/4190-1/http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00047.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00048.htmlhttps://lists.apache.org/thread.html/rc800763a88775ac9abb83b3402bcd0913d41ac65fdfc759af38f2280%40%3Ccommits.mxnet.apache.org%3Ehttps://lists.debian.org/debian-lts-announce/2022/05/msg00048.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Y4QPASQPZO644STRFTLOD35RIRGWWRNI/https://security.gentoo.org/glsa/202003-23https://source.android.com/security/bulletin/2019-11-01https://usn.ubuntu.com/4190-1/
2019-11-13
Published