Debian Libjpeg-Turbo vulnerabilities
18 known vulnerabilities affecting debian/libjpeg-turbo.
Total CVEs
18
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM6LOW10
Vulnerabilities
Page 1 of 1
CVE-2020-17541P3LOWCVSS 8.8fixed in libjpeg-turbo 1:2.0.5-1 (bookworm)2020
CVE-2020-17541 [HIGH] CVE-2020-17541: libjpeg-turbo - Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" ...
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye: resolved (fixed in 1:2.0.5-1)
forky: resolved (fixed in 1:2.0.5-1
debian
CVE-2019-2201P3LOWCVSS 7.8fixed in libjpeg-turbo 1:2.0.5-1 (bookworm)2019
CVE-2019-2201 [HIGH] CVE-2019-2201: libjpeg-turbo - In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possibl...
In generate_jsimd_ycc_rgb_convert_neon of jsimd_arm64_neon.S, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10A
debian
CVE-2016-3616P3HIGHCVSS 8.8fixed in libjpeg-turbo 1:1.4.2-1 (bookworm)2016
CVE-2016-3616 [HIGH] CVE-2016-3616: libjpeg-turbo - The cjpeg utility in libjpeg allows remote attackers to cause a denial of servic...
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
Scope: local
bookworm: resolved (fixed in 1:1.4.2-1)
bullseye: resolved (fixed in 1:1.4.2-1)
forky: resolved (fixed in 1:1.4.2-1)
sid: resolved (fixed in 1:1.4.2-1)
trixie: resolved (fixe
debian
CVE-2020-13790P3HIGHCVSS 8.1fixed in libjpeg-turbo 1:2.0.5-1 (bookworm)2020
CVE-2020-13790 [HIGH] CVE-2020-13790: libjpeg-turbo - libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get...
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye: resolved (fixed in 1:2.0.5-1)
forky: resolved (fixed in 1:2.0.5-1)
sid: resolved (fixed in 1:2.0.5-1)
trixie: resolved (fixed in 1:2.0.5-1)
debian
CVE-2018-11813P4LOWCVSS 7.5fixed in libjpeg-turbo 1:2.0.5-1 (bookworm)2018
CVE-2018-11813 [HIGH] CVE-2018-11813: libjpeg-turbo - libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye: resolved (fixed in 1:2.0.5-1)
forky: resolved (fixed in 1:2.0.5-1)
sid: resolved (fixed in 1:2.0.5-1)
trixie: resolved (fixed in 1:2.0.5-1)
debian
CVE-2013-6629P4LOWCVSS 5.0fixed in libjpeg-turbo 1.3.0-3 (bookworm)2013
CVE-2013-6629 [MEDIUM] CVE-2013-6629: libjpeg-turbo - The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo throu...
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive informat
debian
CVE-2018-11212P4MEDIUMCVSS 6.5fixed in libjpeg-turbo 1:1.4.2-1 (bookworm)2018
CVE-2018-11212 [MEDIUM] CVE-2018-11212: libjpeg-turbo - An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemm...
An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.
Scope: local
bookworm: resolved (fixed in 1:1.4.2-1)
bullseye: resolved (fixed in 1:1.4.2-1)
forky: resolved (fixed in 1:1.4.2-1)
sid: resolved (fixed in 1:1.4.2-1)
trixie: resolv
debian
CVE-2018-1152P4LOWCVSS 6.5fixed in libjpeg-turbo 1:2.0.5-1 (bookworm)2018
CVE-2018-1152 [MEDIUM] CVE-2018-1152: libjpeg-turbo - libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused b...
libjpeg-turbo 1.5.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted BMP image.
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye: resolved (fixed in 1:2.0.5-1)
forky: resolved (fixed in 1:2.0.5-1)
sid: resolved (fixed in 1:2.0.5-1)
trixie: resolved (fixed in 1:2.0.5-1)
debian
CVE-2018-14498P4LOWCVSS 6.5fixed in libjpeg-turbo 1:2.0.5-1 (bookworm)2018
CVE-2018-14498 [MEDIUM] CVE-2018-14498: libjpeg-turbo - get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3....
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye:
debian
CVE-2017-15232P4LOWCVSS 6.5fixed in libjpeg-turbo 1:2.0.5-1 (bookworm)2017
CVE-2017-15232 [MEDIUM] CVE-2017-15232: libjpeg-turbo - libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c v...
libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
Scope: local
bookworm: resolved (fixed in 1:2.0.5-1)
bullseye: resolved (fixed in 1:2.0.5-1)
forky: resolved (fixed in 1:2.0.5-1)
sid: resolved (fixed in 1:2.0.5-1)
trixie: resolved (fixed in 1:2.0.5-1)
debian
CVE-2014-9092P4MEDIUMCVSS 6.5fixed in libjpeg-turbo 1:1.3.1-11 (bookworm)2014
CVE-2014-9092 [MEDIUM] CVE-2014-9092: libjpeg-turbo - libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service ...
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
Scope: local
bookworm: resolved (fixed in 1:1.3.1-11)
bullseye: resolved (fixed in 1:1.3.1-11)
forky: resolved (fixed in 1:1.3.1-11)
sid: resolved (fixed in 1:1.3.1-11)
trixie: resolved (fixed in 1:1.3.1-11)
debian
CVE-2020-14152P4LOWCVSS 7.1fixed in libjpeg-turbo 1:1.5.2-1 (bookworm)2020
CVE-2020-14152 [HIGH] CVE-2020-14152: libjpeg-turbo - In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg...
In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.
Scope: local
bookworm: resolved (fixed in 1:1.5.2-1)
bullseye: resolved (fixed in 1:1.5.2-1)
forky: resolved (fixed in 1:1.5.2-1)
sid: resolved (fixed in 1:1.5.2-1)
trixie: resolved (fixed
debian
CVE-2018-11213P4MEDIUMCVSS 6.5fixed in libjpeg-turbo 1:1.4.2-1 (bookworm)2018
CVE-2018-11213 [MEDIUM] CVE-2018-11213: libjpeg-turbo - An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c...
An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
Scope: local
bookworm: resolved (fixed in 1:1.4.2-1)
bullseye: resolved (fixed in 1:1.4.2-1)
forky: resolved (fixed in 1:1.4.2-1)
sid: resolved (fixed in 1:1.4.2-1)
trixie: resolved (fi
debian
CVE-2018-11214P4MEDIUMCVSS 6.5fixed in libjpeg-turbo 1:1.4.2-1 (bookworm)2018
CVE-2018-11214 [MEDIUM] CVE-2018-11214: libjpeg-turbo - An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c ...
An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.
Scope: local
bookworm: resolved (fixed in 1:1.4.2-1)
bullseye: resolved (fixed in 1:1.4.2-1)
forky: resolved (fixed in 1:1.4.2-1)
sid: resolved (fixed in 1:1.4.2-1)
trixie: resolved (fix
debian
CVE-2020-14153P4LOWCVSS 7.1fixed in libjpeg9 1:9d-1 (sid)2020
CVE-2020-14153 [HIGH] CVE-2020-14153: libjpeg-turbo - In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-boun...
In IJG JPEG (aka libjpeg) from version 8 through 9c, jdhuff.c has an out-of-bounds array read for certain table pointers.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2013-6630P4LOWCVSS 5.0fixed in libjpeg-turbo 1.3.0-3 (bookworm)2013
CVE-2013-6630 [MEDIUM] CVE-2013-6630: libjpeg-turbo - The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Go...
The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory
debian
CVE-2021-46822P4MEDIUMCVSS 5.5fixed in libjpeg-turbo 1:2.1.1-1 (bookworm)2021
CVE-2021-46822 [MEDIUM] CVE-2021-46822: libjpeg-turbo - The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for...
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
Scope: local
bookworm: resolved (fixed in 1:2.1.1-1)
bullseye: open
fork
debian
CVE-2020-35538P4MEDIUMCVSS 5.5fixed in libjpeg-turbo 1:2.0.6-1 (bookworm)2020
CVE-2020-35538 [MEDIUM] CVE-2020-35538: libjpeg-turbo - A crafted input file could cause a null pointer dereference in jcopy_sample_rows...
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
Scope: local
bookworm: resolved (fixed in 1:2.0.6-1)
bullseye: resolved (fixed in 1:2.0.6-1)
forky: resolved (fixed in 1:2.0.6-1)
sid: resolved (fixed in 1:2.0.6-1)
trixie: resolved (fixed in 1:2.0.6-1)
debian