Out-of-bounds read in libjpeg-turbo - CVE-2018-14498
Published: January 13, 2020 / Updated: January 13, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when processing a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries within the get_8bit_row in rdbmp.c. A remote attacker can create a specially crafted file, pass it to the application, trigger out-of-bounds read error and crash the affected application.
Affected software
Amazon Linux AMI
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for x86_64
Ubuntu
Opensuse
Fedora
libjpeg-turbo (Ubuntu package)
libjpeg-turbo (Alpine package)
libjpeg-turbo8 (Ubuntu package)
libjpeg-turbo-progs (Ubuntu package)
libturbojpeg (Ubuntu package)
libjpeg-turbo-test (Ubuntu package)
libjpeg-turbo
Tanzu Greenplum for Kubernetes
Data Computing Appliance (DCA)
VMware Tanzu Operations Manager
How to mitigate CVE-2018-14498
libjpeg-turbo (Ubuntu package) - addressed in versions 1.4.2-0ubuntu3.3, 1.5.2-0ubuntu5.18.04.3, 2.0.1-0ubuntu2.2
libjpeg-turbo (Alpine package) - addressed in versions 1.5.3-r3, 1.5.3-r5
libjpeg-turbo8 (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libjpeg-turbo-progs (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libturbojpeg (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libjpeg-turbo-test (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libjpeg-turbo - update to 1.5.3-7.fc28
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
Data Computing Appliance (DCA) - update to 4.3.0.0
External References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html
- http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.html
- https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9c78a04df4e44ef6487eee99c4258397f4fdca55
- https://github.com/libjpeg-turbo/libjpeg-turbo/issues/258
- https://github.com/mozilla/mozjpeg/issues/299
- https://lists.debian.org/debian-lts-announce/2019/03/msg00021.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7YP4QUEYGHI4Q7GIAVFVKWQ7DJMBYLU/
Related Security Bulletins
- Ubuntu update for libjpeg-turbo
- Multiple vulnerabilities in libjpeg-turbo
- OpenSUSE Linux update for libjpeg-turbo
- OpenSUSE Linux update for libjpeg-turbo
- Amazon Linux AMI update for libjpeg-turbo
- Red Hat update for libjpeg-turbo
- Red Hat update for libjpeg-turbo
- Out-of-bounds read in libjpeg-turbo (Alpine package)
- Ubuntu update for libjpeg-turbo
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- VMware Tanzu products update for libjpeg-turbo
- Fedora 28 update for libjpeg-turbo