CVE-2020-35538
published 2022-08-31CVE-2020-35538: A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.27%
18.5th percentile
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjpeg-turbo | < libjpeg-turbo 1:2.0.6-1 (bookworm) | libjpeg-turbo 1:2.0.6-1 (bookworm) |
| libjpeg-turbo | libjpeg-turbo | — | — |
| libjpeg-turbo | libjpeg-turbo | — | — |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.6-1 | 1:2.0.6-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.6-1 | 1:2.0.6-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.6-1 | 1:2.0.6-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.0.6-1 | 1:2.0.6-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.5.2-0ubuntu5.18.04.6 | 1.5.2-0ubuntu5.18.04.6 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 2.0.3-0ubuntu1.20.04.3 | 2.0.3-0ubuntu1.20.04.3 |
| msrc | azure_eflow | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | none_available | — | — |
| msrc | remote_desktop_client | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_20h2 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
libjpeg-turbo vulnerabilities
osv·2022-09-22·CVSS 7.5
CVE-2018-11813 [HIGH] libjpeg-turbo vulnerabilities
libjpeg-turbo vulnerabilities
It was discovered that libjpeg-turbo incorrectly handled certain EOF
characters. An attacker could possibly use this issue to cause
libjpeg-turbo to consume resource, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2018-11813)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
jpeg files. An attacker could possibly use this issue to cause
libjpeg-turbo to crash, resulting in a denial of service. (CVE-2020-17541,
CVE-2020-35538)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
PPM files. An attacker could use this issue to cause libjpeg-turbo to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-4682
GHSA
GHSA-grwc-h387-x9h2: A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo
ghsa_unreviewed·2022-09-01
CVE-2020-35538 [MEDIUM] CWE-476 GHSA-grwc-h387-x9h2: A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
OSV
CVE-2020-35538: A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo
osv·2022-08-31·CVSS 5.5
CVE-2020-35538 [MEDIUM] CVE-2020-35538: A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2022-09-22·CVSS 7.5
CVE-2020-35538 [HIGH] libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: Several security issues were fixed in libjpeg-turbo.
It was discovered that libjpeg-turbo incorrectly handled certain EOF
characters. An attacker could possibly use this issue to cause
libjpeg-turbo to consume resource, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2018-11813)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
jpeg files. An attacker could possibly use this issue to cause
libjpeg-turbo to crash, resulting in a denial of service. (CVE-2020-17541,
CVE-2020-35538)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
PPM files. An attacker could use this issue to cause libjpeg-turbo to
crash, resulting in a denial of service, or possibly execute arb
Microsoft
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
vendor_msrc·2022-08-09·CVSS 5.5
CVE-2020-35538 [MEDIUM] CWE-476 A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
redhat: redhat
Customer Action Required: Ye
Red Hat
libjpeg-turbo: Null pointer dereference in jcopy_sample_rows() function
vendor_redhat·2020-07-06·CVSS 5.5
CVE-2020-35538 [MEDIUM] CWE-476 libjpeg-turbo: Null pointer dereference in jcopy_sample_rows() function
libjpeg-turbo: Null pointer dereference in jcopy_sample_rows() function
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
A vulnerability was found in libjpeg-turbo where a segmentation fault occurs due to a NULL pointer passing to jcopy_sample_rows(). You may see this error statement: "Corrupt JPEG data: premature end of data segment". When processed by a libjpeg-turbo, a crafted input file could cause a crash, leading to a denial of service.
Statement: This vulnerability is considered low severity rather than moderate because it primarily results in a denial of service (DoS) through a crash, without posing a direct risk of code execution or information disclosure. The issue arises due to a NULL pointer dereference when
Debian
CVE-2020-35538: libjpeg-turbo - A crafted input file could cause a null pointer dereference in jcopy_sample_rows...
vendor_debian·2020·CVSS 5.5
CVE-2020-35538 [MEDIUM] CVE-2020-35538: libjpeg-turbo - A crafted input file could cause a null pointer dereference in jcopy_sample_rows...
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
Scope: local
bookworm: resolved (fixed in 1:2.0.6-1)
bullseye: resolved (fixed in 1:2.0.6-1)
forky: resolved (fixed in 1:2.0.6-1)
sid: resolved (fixed in 1:2.0.6-1)
trixie: resolved (fixed in 1:2.0.6-1)
No detection rules found.
No public exploits indexed.
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9120a247436e84c0b4eea828cb11e8f665fcde30https://github.com/libjpeg-turbo/libjpeg-turbo/issues/441https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9120a247436e84c0b4eea828cb11e8f665fcde30https://github.com/libjpeg-turbo/libjpeg-turbo/issues/441
2022-08-31
Published