The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade libjpeg-turbo | Aug 22, 2024 | Dec 21, 2018 |
| Huawei Euleros 2_0_sp8 | — | Upgrade libjpeg-turboUpgrade libjpeg-turbo-devel | Aug 31, 2020 | Dec 21, 2018 |
| Suse | — | Upgrade libjpeg62Upgrade libjpeg8Upgrade libjpeg62-develUpgrade libjpeg8-32bitUpgrade libturbojpeg0Upgrade libjpeg8-devel | Aug 9, 2024 | Dec 21, 2018 |
| Ubuntu | — | Upgrade libjpeg-turbo8 | Nov 14, 2019 | Dec 21, 2018 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Dec 21, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub