Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Ubuntu 12.04 ESM USN-3706-2: Critical Libjpeg-Turbo Remote Exploits

Ubuntu Large Esm H500
libjpeg-turbo could be made to crash or run programs as your login if it opened a specially crafted file.
=========================================================================Ubuntu Security Notice USN-3706-2
July 10, 2018

libjpeg-turbo vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 ESM

Summary:

libjpeg-turbo could be made to crash or run programs as your login if
it opened a specially crafted file.

Software Description:
- libjpeg-turbo: library for handling JPEG files

Details:

USN-3706-1 fixed a vulnerability in libjpeg-turbo. This update provides
the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

 It was discovered that libjpeg-turbo incorrectly handled certain
 malformed JPEG images. If a user or automated system were tricked into
 opening a specially crafted JPEG image, a remote attacker could cause
 libjpeg-turbo to crash, resulting in a denial of service, or possibly
 execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
  libjpeg-turbo8                  1.1.90+svn733-0ubuntu4.5

In general, a standard system update will make all the necessary
changes.

References:
  https://ubuntu.com/security/notices/USN-3706-2
  https://ubuntu.com/security/notices/USN-3706-1
  CVE-2014-9092, CVE-2016-3616, CVE-2018-11212, CVE-2018-11213,
  CVE-2018-11214, CVE-2018-1152

Ubuntu 12.04 ESM USN-3706-2: Critical Libjpeg-Turbo Remote Exploits

ubuntu
Calendar Grey July 10, 2018
Dist Ubuntu Esm H88
Ubuntu Security Notice USN-3706-2 July 10, 2018 libjpeg-turbo vulnerabilities A security issue affec
libjpeg-turbo could be made to crash or run programs as your login if it opened a specially crafted file.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM:   libjpeg-turbo8                  1.1.90+svn733-0ubuntu4.5 In general, a standard system update will make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-3706-2

  https://ubuntu.com/security/notices/USN-3706-1

  CVE-2014-9092, CVE-2016-3616, CVE-2018-11212, CVE-2018-11213,

  CVE-2018-11214, CVE-2018-1152

Severity
critical
Lowest
Low
Medium
High
Critical

July 10, 2018

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here