CVE-2020-17541
published 2021-06-01CVE-2020-17541: Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.73%
84.3th percentile
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjpeg-turbo | < libjpeg-turbo 1:2.0.5-1 (bookworm) | libjpeg-turbo 1:2.0.5-1 (bookworm) |
| libjpeg-turbo | libjpeg-turbo | < 2.0.4 | 2.0.4 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.5-1 | 1:2.0.5-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.5.2-0ubuntu5.18.04.6 | 1.5.2-0ubuntu5.18.04.6 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 2.0.3-0ubuntu1.20.04.3 | 2.0.3-0ubuntu1.20.04.3 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.3.0-0ubuntu2.1+esm2 | 1.3.0-0ubuntu2.1+esm2 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.4.2-0ubuntu3.4+esm1 | 1.4.2-0ubuntu3.4+esm1 |
| msrc | cbl2_libjpeg-turbo_2.0.0-9_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_libjpeg-turbo_2.0.0-7_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libjpeg-turbo vulnerabilities
osv·2022-09-22·CVSS 7.5
CVE-2018-11813 [HIGH] libjpeg-turbo vulnerabilities
libjpeg-turbo vulnerabilities
It was discovered that libjpeg-turbo incorrectly handled certain EOF
characters. An attacker could possibly use this issue to cause
libjpeg-turbo to consume resource, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2018-11813)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
jpeg files. An attacker could possibly use this issue to cause
libjpeg-turbo to crash, resulting in a denial of service. (CVE-2020-17541,
CVE-2020-35538)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
PPM files. An attacker could use this issue to cause libjpeg-turbo to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-4682
OSV
libjpeg-turbo vulnerabilities
osv·2022-08-08·CVSS 7.5
CVE-2018-11813 [HIGH] libjpeg-turbo vulnerabilities
libjpeg-turbo vulnerabilities
It was discovered that libjpeg-turbo was not properly handling EOF characters,
which could lead to excessive memory consumption through the execution of a
large loop. An attacker could possibly use this issue to cause a denial of
service. (CVE-2018-11813)
It was discovered that libjpeg-turbo was not properly performing bounds
check operations, which could lead to a heap-based buffer overread. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 14.04 ESM. (CVE-2018-14498)
It was discovered that libjpeg-turbo was not properly limiting the amount of
main memory being consumed by the system during decompression or multi-pass
comp
GHSA
GHSA-vhxw-68wq-v5j9: Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component
ghsa_unreviewed·2022-05-24
CVE-2020-17541 [HIGH] CWE-787 GHSA-vhxw-68wq-v5j9: Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
OSV
CVE-2020-17541: Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component
osv·2021-06-01·CVSS 8.8
CVE-2020-17541 [HIGH] CVE-2020-17541: Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2022-09-22·CVSS 7.5
CVE-2020-35538 [HIGH] libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: Several security issues were fixed in libjpeg-turbo.
It was discovered that libjpeg-turbo incorrectly handled certain EOF
characters. An attacker could possibly use this issue to cause
libjpeg-turbo to consume resource, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2018-11813)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
jpeg files. An attacker could possibly use this issue to cause
libjpeg-turbo to crash, resulting in a denial of service. (CVE-2020-17541,
CVE-2020-35538)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
PPM files. An attacker could use this issue to cause libjpeg-turbo to
crash, resulting in a denial of service, or possibly execute arb
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2022-08-08·CVSS 7.5
CVE-2020-17541 [HIGH] libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: Several security issues were fixed in libjpeg-turbo.
It was discovered that libjpeg-turbo was not properly handling EOF characters,
which could lead to excessive memory consumption through the execution of a
large loop. An attacker could possibly use this issue to cause a denial of
service. (CVE-2018-11813)
It was discovered that libjpeg-turbo was not properly performing bounds
check operations, which could lead to a heap-based buffer overread. If a user
or automated system were tricked into opening a specially crafted file, an
attacker could possibly use this issue to cause a denial of service. This
issue only affected Ubuntu 14.04 ESM. (CVE-2018-14498)
It was discovered that libjpeg-turbo was not properly limiting the amount of
main memor
Microsoft
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial
vendor_msrc·2021-06-08·CVSS 8.8
CVE-2020-17541 [HIGH] CWE-787 Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products
Red Hat
libjpeg-turbo: Stack-based buffer overflow in the "transform" component
vendor_redhat·2021-06-01·CVSS 8.8
CVE-2020-17541 [HIGH] CWE-119 libjpeg-turbo: Stack-based buffer overflow in the "transform" component
libjpeg-turbo: Stack-based buffer overflow in the "transform" component
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
A stack-based buffer overflow flaw was found in libjpeg-turbo library in the tranform component. An attacker may use this flaw to input a malicious image file to an application utilizing this library, leading to arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security
Debian
CVE-2020-17541: libjpeg-turbo - Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" ...
vendor_debian·2020·CVSS 8.8
CVE-2020-17541 [HIGH] CVE-2020-17541: libjpeg-turbo - Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" ...
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye: resolved (fixed in 1:2.0.5-1)
forky: resolved (fixed in 1:2.0.5-1)
sid: resolved (fixed in 1:2.0.5-1)
trixie: resolved (fixed in 1:2.0.5-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-06-01
Published