CVE-2020-14152Uncontrolled Resource Consumption in Libjpeg

Severity
7.1HIGHNVD
OSV8.8
EPSS
1.2%
top 21.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 15
Latest updateJul 16

Description

In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages2 packages

NVDijg/libjpeg< 9d
Debianlibjpeg-turbo/libjpeg-turbo< 1:1.5.2-1+3

Also affects: Debian Linux 9.0

🔴Vulnerability Details

6
GHSA
Fiona affected by CVE-2020-14152 related to madler-zlib2024-07-16
OSV
Fiona affected by CVE-2020-14152 related to madler-zlib2024-07-16
GHSA
GHSA-q4xh-9r6f-9fg6: In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs2022-05-24
OSV
libjpeg9 vulnerabilities2022-03-23
CVEList
CVE-2020-14152: In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs2020-06-15

📋Vendor Advisories

7
Ubuntu
libjpeg-turbo vulnerabilities2022-08-08
Ubuntu
Libjpeg6b vulnerabilities2022-06-30
Ubuntu
Libjpeg6b vulnerabilities2022-06-30
Ubuntu
libjpeg9 vulnerabilities2022-03-23
Red Hat
libjpeg: improper handling of max_memory_to_use setting can lead to excessive memory consumption2020-06-11

💬Community

1
Bugzilla
CVE-2020-14152 libjpeg: improper handling of max_memory_to_use setting can lead to excessive memory consumption2020-06-19
CVE-2020-14152 — Uncontrolled Resource Consumption | cvebase