CVE-2021-29390
published 2023-08-22CVE-2021-29390: libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
PriorityP429high7.1CVSS 3.1
AVNACLPRNUIRSUCLINAH
EPSS
0.71%
49.4th percentile
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjpeg-turbo | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| libjpeg-turbo | libjpeg-turbo | — | — |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 2.1.2-0ubuntu1 | 2.1.2-0ubuntu1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 2.1.5-2ubuntu1 | 2.1.5-2ubuntu1 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
osv7.1HIGH
vendor_debian7.1LOW
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2021-29390: libjpeg-turbo version 2
osv·2023-08-22·CVSS 7.1
CVE-2021-29390 [HIGH] CVE-2021-29390: libjpeg-turbo version 2
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
GHSA
GHSA-3f9q-r2pw-87vm: libjpeg-turbo version 2
ghsa_unreviewed·2023-08-22
CVE-2021-29390 [HIGH] CWE-787 GHSA-3f9q-r2pw-87vm: libjpeg-turbo version 2
libjpeg-turbo version 2.0.90 is vulnerable to a heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c.
Red Hat
libjpeg-turbo: heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c
vendor_redhat·2023-08-22·CVSS 7.1
CVE-2021-29390 [HIGH] CWE-125 libjpeg-turbo: heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c
libjpeg-turbo: heap-buffer-overflow vulnerability in decompress_smooth_data in jdcoefct.c
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
A heap buffer over-read flaw was found in libjpeg-turbo. For certain types of smoothed jpeg images, the decompress_smooth_data() function may improperly enter a condition statement that leads to heap memory read of uninitialized data, which may cause an application crash or loss of confidentiality.
Statement: The amount of memory read is very small and not controllable by an attacker, which lowers the impact of this flaw to Moderate.
Package: libjpeg-turbo (Red Hat Enterprise Linux 6) - Out of support scope
Package: libjpeg-turbo (Red Hat Enterprise Linux 7) - Out of support scope
Pa
Debian
CVE-2021-29390: libjpeg-turbo - libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in deco...
vendor_debian·2021·CVSS 7.1
CVE-2021-29390 [HIGH] CVE-2021-29390: libjpeg-turbo - libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in deco...
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1943797https://github.com/libjpeg-turbo/libjpeg-turbo/blob/4e52b66f342a803d3b8099b79607e3158d3a241c/jdcoefct.c#L595https://github.com/libjpeg-turbo/libjpeg-turbo/commits/main/jdcoefct.chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27NR3KG553CG6LGPMP6SHWEVHTYPL6RC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/https://bugzilla.redhat.com/show_bug.cgi?id=1943797https://github.com/libjpeg-turbo/libjpeg-turbo/blob/4e52b66f342a803d3b8099b79607e3158d3a241c/jdcoefct.c#L595https://github.com/libjpeg-turbo/libjpeg-turbo/commits/main/jdcoefct.chttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/27NR3KG553CG6LGPMP6SHWEVHTYPL6RC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6T655QF7CQ3DYAMPFV7IECQYGDEUIVVT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KUQ7CTX3W372X3UY56VVNAHCH6H2F4X3/
2023-08-22
Published