cbcvebase.
CVE-2020-17541
published 2021-06-01

CVE-2020-17541: Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and…

PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.73%
84.3th percentile
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianlibjpeg-turbo< libjpeg-turbo 1:2.0.5-1 (bookworm)libjpeg-turbo 1:2.0.5-1 (bookworm)
libjpeg-turbolibjpeg-turbo< 2.0.42.0.4
libjpeg-turbolibjpeg-turbo>= 0 < 1:2.0.5-11:2.0.5-1
libjpeg-turbolibjpeg-turbo>= 0 < 1:2.0.5-11:2.0.5-1
libjpeg-turbolibjpeg-turbo>= 0 < 1:2.0.5-11:2.0.5-1
libjpeg-turbolibjpeg-turbo>= 0 < 1:2.0.5-11:2.0.5-1
libjpeg-turbolibjpeg-turbo>= 0 < 1.5.2-0ubuntu5.18.04.61.5.2-0ubuntu5.18.04.6
libjpeg-turbolibjpeg-turbo>= 0 < 2.0.3-0ubuntu1.20.04.32.0.3-0ubuntu1.20.04.3
libjpeg-turbolibjpeg-turbo>= 0 < 1.3.0-0ubuntu2.1+esm21.3.0-0ubuntu2.1+esm2
libjpeg-turbolibjpeg-turbo>= 0 < 1.4.2-0ubuntu3.4+esm11.4.2-0ubuntu3.4+esm1
msrccbl2_libjpeg-turbo_2.0.0-9_on_cbl_mariner_2.0
msrccm1_libjpeg-turbo_2.0.0-7_on_cbl_mariner_1.0

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.