Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 8: DLA-1638-1 Critical: libjpeg-turbo DoS Issues

debian lts
Calendar Grey January 22, 2019
Dist Debian Esm H88
Several vulnerabilities addressed in libjpeg-turbo to protect against denial-of-service threats; suggested updates for Debian environments.
Several vulnerabilities have been resolved in libjpeg-turbo, Debian's default JPEG implemenation

Summary

The cjpeg utility in libjpeg allowed remote attackers to cause a
denial of service (NULL pointer dereference and application crash) or
execute arbitrary code via a crafted file.

This issue got fixed by the same patch that fixed CVE-2018-11213 and
CVE-2018-11214.

CVE-2018-1152

libjpeg-turbo has been found vulnerable to a denial of service
vulnerability caused by a divide by zero when processing a crafted
BMP image. The issue has been resolved by a boundary check.

CVE-2018-11212

The alloc_sarray function in jmemmgr.c allowed remote attackers to
cause a denial of service (divide-by-zero error) via a crafted file.

The issue has been addressed by checking the image size when reading
a targa file and throwing an error when image width or height is 0.

CVE-2018-11213
CVE-2018-11214

The get_text_gray_row and get_text_rgb_row functions in rdppm.c both
allowed remote attackers to cause a denial of service (Segmentation
fault) via a crafted file.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

<pre><font face="Courier">Package: libjpeg-turbo
Version: 1:1.3.1-12+deb8u1
CVE ID: CVE-2016-3616 CVE-2018-1152 CVE-2018-11212 CVE-2018-11213
Debian Bug: #819969 #902950 #902176

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here