Out-of-bounds read in libjpeg-turbo - CVE-2020-13790
Published: June 10, 2020 / Updated: November 19, 2020
Vulnerability identifier: #VU28930
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13790
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file. A remote attacker can perform a denial of service attack.
Affected software
libjpeg-turbo
Gentoo Linux
Slackware Linux
Opensuse
openEuler
Fedora
TensorFlow
Netcool Operations Insight
Ansible Automation Platform
libjpeg-turbo (Ubuntu package)
libjpeg-turbo (Alpine package)
libjpeg-turbo
libjpeg-turbo-debuginfo
libjpeg-turbo-debugsource
libjpeg-turbo-devel
libjpeg-turbo-help
mingw-libjpeg-turbo
mozjpeg
IBM Cloud Pak for Watson AIOps
Business Automation Insights
IBM Qradar SIEM
Red Hat OpenShift Container Platform
Gentoo Linux
Slackware Linux
Opensuse
openEuler
Fedora
TensorFlow
Netcool Operations Insight
Ansible Automation Platform
libjpeg-turbo (Ubuntu package)
libjpeg-turbo (Alpine package)
libjpeg-turbo
libjpeg-turbo-debuginfo
libjpeg-turbo-debugsource
libjpeg-turbo-devel
libjpeg-turbo-help
mingw-libjpeg-turbo
mozjpeg
IBM Cloud Pak for Watson AIOps
Business Automation Insights
IBM Qradar SIEM
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-13790
Install update from vendor's website.
libjpeg-turbo - update to 2.0.5
TensorFlow - addressed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2
Netcool Operations Insight - update to 1.6.15
libjpeg-turbo (Ubuntu package) - addressed in versions 1.4.2-0ubuntu3.4, 1.5.2-0ubuntu5.18.04.4, 2.0.3-0ubuntu1.19.10.1, 2.0.3-0ubuntu1.20.04.1
mozjpeg - update to 2.0.5
libjpeg-turbo (Alpine package) - addressed in versions 2.0.4-r1, 2.0.4-r2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF02
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
libjpeg-turbo - update to 2.0.4-1
libjpeg-turbo-debuginfo - update to 2.0.4-1
libjpeg-turbo-debugsource - update to 2.0.4-1
libjpeg-turbo-devel - update to 2.0.4-1
libjpeg-turbo-help - update to 2.0.4-1
mingw-libjpeg-turbo - update to 2.0.4-3.fc32
libjpeg-turbo - update to 2.0.4-3.fc32
Ansible Automation Platform - addressed in versions 2.4, 2.5
Red Hat OpenShift Container Platform - update to 4.14.52
TensorFlow - addressed in versions 1.15.5, 2.0.4, 2.1.3, 2.2.2, 2.3.2
Netcool Operations Insight - update to 1.6.15
libjpeg-turbo (Ubuntu package) - addressed in versions 1.4.2-0ubuntu3.4, 1.5.2-0ubuntu5.18.04.4, 2.0.3-0ubuntu1.19.10.1, 2.0.3-0ubuntu1.20.04.1
mozjpeg - update to 2.0.5
libjpeg-turbo (Alpine package) - addressed in versions 2.0.4-r1, 2.0.4-r2
IBM Cloud Pak for Watson AIOps - update to 4.10.0
IBM Qradar SIEM - update to 7.5.0 Update Pack 12 IF02
Business Automation Insights - addressed in versions 24.0.0.0.4, 24.0.1.0.4
libjpeg-turbo - update to 2.0.4-1
libjpeg-turbo-debuginfo - update to 2.0.4-1
libjpeg-turbo-debugsource - update to 2.0.4-1
libjpeg-turbo-devel - update to 2.0.4-1
libjpeg-turbo-help - update to 2.0.4-1
mingw-libjpeg-turbo - update to 2.0.4-3.fc32
libjpeg-turbo - update to 2.0.4-3.fc32
Ansible Automation Platform - addressed in versions 2.4, 2.5
Red Hat OpenShift Container Platform - update to 4.14.52
External References
Related Security Bulletins
- Denial of service in libjpeg-turbo
- Denial of service in Mozilla mozjpeg
- Ubuntu update for libjpeg-turbo
- Slackware Linux update for libjpeg-turbo
- Out-of-bounds read in libjpeg-turbo (Alpine package)
- OpenSUSE Linux update for libjpeg-turbo
- OpenSUSE Linux update for libjpeg-turbo
- Gentoo update for libjpeg-turbo
- Multiple vulnerabilities in TensorFlow
- openEuler 20.03 LTS update for libjpeg-turbo-2.0.4-1
- Fedora 32 update for libjpeg-turbo
- Fedora 32 update for mingw-libjpeg-turbo
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.14
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in Ansible Automation Platform 2.5 packages
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in Ansible Automation Platform 2.4 packages
- Multiple vulnerabilities in IBM Business Automation Insights
- Multiple vulnerabilities in Netcool Operations Insight