Out-of-bounds read in libjpeg-turbo - CVE-2020-13790

 

Out-of-bounds read in libjpeg-turbo - CVE-2020-13790

Published: June 10, 2020 / Updated: November 19, 2020


Vulnerability identifier: #VU28930
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13790
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file. A remote attacker can perform a denial of service attack.


Affected software

libjpeg-turbo
Gentoo Linux
Slackware Linux
Opensuse
openEuler
Fedora
TensorFlow
Netcool Operations Insight
Ansible Automation Platform
libjpeg-turbo (Ubuntu package)
libjpeg-turbo (Alpine package)
libjpeg-turbo
libjpeg-turbo-debuginfo
libjpeg-turbo-debugsource
libjpeg-turbo-devel
libjpeg-turbo-help
mingw-libjpeg-turbo
mozjpeg
IBM Cloud Pak for Watson AIOps
Business Automation Insights
IBM Qradar SIEM
Red Hat OpenShift Container Platform

How to mitigate CVE-2020-13790

Install update from vendor's website.

libjpeg-turbo - update to 2.0.5
TensorFlow - addressed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2
Netcool Operations Insight - update to 1.6.15
libjpeg-turbo (Ubuntu package) - addressed in versions 1.4.2-0ubuntu3.4, 1.5.2-0ubuntu5.18.04.4, 2.0.3-0ubuntu1.19.10.1, 2.0.3-0ubuntu1.20.04.1
mozjpeg - update to 2.0.5
libjpeg-turbo (Alpine package) - addressed in versions 2.0.4-r1, 2.0.4-r2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF02
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
libjpeg-turbo - update to 2.0.4-1
libjpeg-turbo-debuginfo - update to 2.0.4-1
libjpeg-turbo-debugsource - update to 2.0.4-1
libjpeg-turbo-devel - update to 2.0.4-1
libjpeg-turbo-help - update to 2.0.4-1
mingw-libjpeg-turbo - update to 2.0.4-3.fc32
libjpeg-turbo - update to 2.0.4-3.fc32
Ansible Automation Platform - addressed in versions 2.4, 2.5
Red Hat OpenShift Container Platform - update to 4.14.52

External References

Related Security Bulletins