CVE-2021-46822
published 2022-06-18CVE-2021-46822: The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit…
PriorityP420medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.01%
59.0th percentile
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libjpeg-turbo | < libjpeg-turbo 1:2.1.1-1 (bookworm) | libjpeg-turbo 1:2.1.1-1 (bookworm) |
| libjpeg-turbo | libjpeg-turbo | <= 2.0.90 | — |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.1.1-1 | 1:2.1.1-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.1.1-1 | 1:2.1.1-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:2.1.1-1 | 1:2.1.1-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1.5.2-0ubuntu5.18.04.6 | 1.5.2-0ubuntu5.18.04.6 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 2.0.3-0ubuntu1.20.04.3 | 2.0.3-0ubuntu1.20.04.3 |
| msrc | cm1_libjpeg-turbo_2.1.2-1_on_cbl_mariner_1.0 | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2022-09-22·CVSS 7.5
CVE-2020-35538 [HIGH] libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: Several security issues were fixed in libjpeg-turbo.
It was discovered that libjpeg-turbo incorrectly handled certain EOF
characters. An attacker could possibly use this issue to cause
libjpeg-turbo to consume resource, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2018-11813)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
jpeg files. An attacker could possibly use this issue to cause
libjpeg-turbo to crash, resulting in a denial of service. (CVE-2020-17541,
CVE-2020-35538)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
PPM files. An attacker could use this issue to cause libjpeg-turbo to
crash, resulting in a denial of service, or possibly execute arb
Microsoft
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This
vendor_msrc·2022-06-14·CVSS 5.5
CVE-2021-46822 [MEDIUM] CWE-787 The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post f
Red Hat
libjpeg-turbo: heap buffer overflow in get_word_rgb_row() in rdppm.c
vendor_redhat·2021-04-07·CVSS 5.5
CVE-2021-46822 [MEDIUM] CWE-119 libjpeg-turbo: heap buffer overflow in get_word_rgb_row() in rdppm.c
libjpeg-turbo: heap buffer overflow in get_word_rgb_row() in rdppm.c
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
A heap-based buffer overflow vulnerability was found in libjpeg-turbo in the get_word_rgb_row() function in rdppm.c. The flaw occurs when the PPM reader in libjpeg-turbo mishandles use of the tjLoadImage() function for loading a 16-bit binary PPM file into a grayscale uncompressed image buffer and then loading a 16-bit binary PGM file into an RGB uncompressed image buffer. This flaw allows a remote attacker to persuade a victim to open a
Debian
CVE-2021-46822: libjpeg-turbo - The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for...
vendor_debian·2021·CVSS 5.5
CVE-2021-46822 [MEDIUM] CVE-2021-46822: libjpeg-turbo - The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for...
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
Scope: local
bookworm: resolved (fixed in 1:2.1.1-1)
bullseye: open
forky: resolved (fixed in 1:2.1.1-1)
sid: resolved (fixed in 1:2.1.1-1)
trixie: resolved (fixed in 1:2.1.1-1)
OSV
libjpeg-turbo vulnerabilities
osv·2022-09-22·CVSS 7.5
CVE-2018-11813 [HIGH] libjpeg-turbo vulnerabilities
libjpeg-turbo vulnerabilities
It was discovered that libjpeg-turbo incorrectly handled certain EOF
characters. An attacker could possibly use this issue to cause
libjpeg-turbo to consume resource, leading to a denial of service. This
issue only affected Ubuntu 18.04 LTS. (CVE-2018-11813)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
jpeg files. An attacker could possibly use this issue to cause
libjpeg-turbo to crash, resulting in a denial of service. (CVE-2020-17541,
CVE-2020-35538)
It was discovered that libjpeg-turbo incorrectly handled certain malformed
PPM files. An attacker could use this issue to cause libjpeg-turbo to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-4682
GHSA
GHSA-p468-hq86-gghc: The PPM reader in libjpeg-turbo through 2
ghsa_unreviewed·2022-06-19
CVE-2021-46822 [MEDIUM] CWE-787 GHSA-p468-hq86-gghc: The PPM reader in libjpeg-turbo through 2
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
OSV
CVE-2021-46822: The PPM reader in libjpeg-turbo through 2
osv·2022-06-18·CVSS 5.5
CVE-2021-46822 [MEDIUM] CVE-2021-46822: The PPM reader in libjpeg-turbo through 2
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://exchange.xforce.ibmcloud.com/vulnerabilities/221567https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f35fd27ec641c42d6b115bfa595e483ec58188d2https://exchange.xforce.ibmcloud.com/vulnerabilities/221567https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f35fd27ec641c42d6b115bfa595e483ec58188d2
2022-06-18
Published