Out-of-bounds read in libjpeg-turbo - CVE-2018-14498

 

Out-of-bounds read in libjpeg-turbo - CVE-2018-14498

Published: January 13, 2020 / Updated: January 13, 2020


Vulnerability identifier: #VU24203
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-14498
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to a boundary condition when processing a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries within the get_8bit_row in rdbmp.c. A remote attacker can create a specially crafted file, pass it to the application, trigger out-of-bounds read error and crash the affected application.


Affected software

libjpeg-turbo
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Ubuntu
Opensuse
Fedora
libjpeg-turbo (Ubuntu package)
libjpeg-turbo (Alpine package)
libjpeg-turbo8 (Ubuntu package)
libjpeg-turbo-progs (Ubuntu package)
libturbojpeg (Ubuntu package)
libjpeg-turbo-test (Ubuntu package)
libjpeg-turbo
Tanzu Greenplum for Kubernetes
Data Computing Appliance (DCA)
VMware Tanzu Operations Manager

How to mitigate CVE-2018-14498

Install update from vendor's website.

libjpeg-turbo - update to 2.0.0
libjpeg-turbo (Ubuntu package) - addressed in versions 1.4.2-0ubuntu3.3, 1.5.2-0ubuntu5.18.04.3, 2.0.1-0ubuntu2.2
libjpeg-turbo (Alpine package) - addressed in versions 1.5.3-r3, 1.5.3-r5
libjpeg-turbo8 (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libjpeg-turbo-progs (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libturbojpeg (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libjpeg-turbo-test (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libjpeg-turbo - update to 1.5.3-7.fc28
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
Data Computing Appliance (DCA) - update to 4.3.0.0

External References

Related Security Bulletins