CVE-2020-14153
published 2020-06-15CVE-2020-14153: In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
PriorityP424high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
1.08%
61.2th percentile
In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjpeg-turbo | < libjpeg9 1:9d-1 (sid) | libjpeg9 1:9d-1 (sid) |
| debian | libjpeg9 | < libjpeg9 1:9d-1 (sid) | libjpeg9 1:9d-1 (sid) |
| ijg | libjpeg | 8 – 9c | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:P
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libjpeg9 vulnerabilities
vendor_ubuntu·2022-03-23·CVSS 8.8
CVE-2020-14153 [HIGH] libjpeg9 vulnerabilities
Title: libjpeg9 vulnerabilities
Summary: Several security issues were fixed in libjpeg9.
Aladdin Mubaied discovered that the cjpeg utility in libjpeg9 did not properly
validate the input image's size. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2016-3616)
It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
certain input. An attacker could possibly use these issues to cause a denial of
service. (CVE-2018-11212, CVE-2018-11813, CVE-2020-14152, CVE-2020-14153)
It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
memory when supplied with certain input. An attacker could possibly use these
issues to cause a denial of service or execute arbitrary code.
(CVE-2018-11213, CVE-2018-11214)
Instru
Red Hat
libjpeg: out-of-bounds read for certain table pointers in jdhuff.c
vendor_redhat·2020-06-11·CVSS 7.1
CVE-2020-14153 [HIGH] CWE-125 libjpeg: out-of-bounds read for certain table pointers in jdhuff.c
libjpeg: out-of-bounds read for certain table pointers in jdhuff.c
In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
Statement: Red Hat Enterprise Linux 6 and later versions ships libjpeg-turbo which already contains the fixes, thus these products are not affected.
Package: libjpeg (Red Hat Enterprise Linux 5) - Out of support scope
Package: libjpeg-turbo (Red Hat Enterprise Linux 6) - Not affected
Package: libjpeg-turbo (Red Hat Enterprise Linux 7) - Not affected
Package: libjpeg-turbo (Red Hat Enterprise Linux 8) - Not affected
Debian
CVE-2020-14153: libjpeg-turbo - In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-boun...
vendor_debian·2020·CVSS 7.1
CVE-2020-14153 [HIGH] CVE-2020-14153: libjpeg-turbo - In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-boun...
In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-9829-xpvg-xp5h: In IJG JPEG (aka libjpeg) before 9d, jdhuff
ghsa_unreviewed·2022-05-24
CVE-2020-14153 [MEDIUM] CWE-125 GHSA-9829-xpvg-xp5h: In IJG JPEG (aka libjpeg) before 9d, jdhuff
In IJG JPEG (aka libjpeg) before 9d, jdhuff.c has an out-of-bounds array read for certain table pointers.
OSV
libjpeg9 vulnerabilities
osv·2022-03-23·CVSS 8.8
CVE-2016-3616 [HIGH] libjpeg9 vulnerabilities
libjpeg9 vulnerabilities
Aladdin Mubaied discovered that the cjpeg utility in libjpeg9 did not properly
validate the input image's size. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2016-3616)
It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
certain input. An attacker could possibly use these issues to cause a denial of
service. (CVE-2018-11212, CVE-2018-11813, CVE-2020-14152, CVE-2020-14153)
It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
memory when supplied with certain input. An attacker could possibly use these
issues to cause a denial of service or execute arbitrary code.
(CVE-2018-11213, CVE-2018-11214)
OSV
CVE-2020-14153: In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff
osv·2020-06-15·CVSS 7.1
CVE-2020-14153 [HIGH] CVE-2020-14153: In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff
In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
No detection rules found.
No public exploits indexed.
2020-06-15
Published