Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8 MGASA-2022-0353 Moderate: libjpeg-turbo Heap Overflow Threat

mageia
Calendar Grey October 1, 2022
Dist Mageia Esm H88
The Mageia security notice MGASA-2022-0354 highlights a critical buffer overflow vulnerability found in libjpeg-turbo, specifically impacting version 2.0.90.
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into ...

Summary

The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c. (CVE-2021-46822)

References

- https://bugs.mageia.org/show_bug.cgi?id=30886

- https://ubuntu.com/security/notices/USN-5631-1

- https://github.com/libjpeg-turbo/libjpeg-turbo/blob/2.0.8-esr/ChangeLog.md

- https://www.cve.org/CVERecord?id=CVE-2021-46822

Resolution

SRPMS

- 8/core/libjpeg-2.0.8-1.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 01 Oct 2022
URL: https://advisories.mageia.org/MGASA-2022-0353.html
Type: security
CVE: CVE-2021-46822

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here