Buffer overflow in libjpeg - CVE-2020-14152
Published: June 17, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack or disclose sensitive information.
The vulnerability exists due to a boundary error in "jpeg_mem_available()" function in "jmemnobs.c" file in djpeg. A remote attacker can create a specially crafted file, trick the victim into opening it, trigger memory corruption and gain access to sensitive information or cause a denial of service condition on the target system.
Affected software
Ubuntu
libjpeg-turbo8 (Ubuntu package)
libjpeg-turbo-progs (Ubuntu package)
libturbojpeg (Ubuntu package)
libjpeg-turbo-test (Ubuntu package)
libjpeg62 (Ubuntu package)
Tanzu Greenplum for Kubernetes
VMware Tanzu Operations Manager
How to mitigate CVE-2020-14152
libjpeg-turbo8 (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libjpeg-turbo-progs (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libturbojpeg (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
libjpeg-turbo-test (Ubuntu package) - update to 1.4.20ubuntu3.4+esm1
Tanzu Greenplum for Kubernetes - update to 2.0.0
VMware Tanzu Operations Manager - addressed in versions 2.7.25, 2.8.16, 2.9.12, 2.10.39
libjpeg62 (Ubuntu package) - update to 6 b14ubuntu1+esm1