Heap-based buffer overflow in Artifex jbig2dec - CVE-2020-12268

 

Heap-based buffer overflow in Artifex jbig2dec - CVE-2020-12268

Published: June 25, 2020


Vulnerability identifier: #VU29247
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12268
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the jbig2_image_compose() function in jbig2_image.c when processing JPEG files in Artifex jbig2dec. A remote attacker can pass specially crafted JPEG file to the application, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Artifex jbig2dec
jbig2dec (Alpine package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
jbig2dec
libjbig2dec0 (Ubuntu package)
jbig2dec (Ubuntu package)
jbig2dec (Red Hat package)
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Opensuse
Ubuntu

How to mitigate CVE-2020-12268

Install updates from vendor's website.

Artifex jbig2dec - update to 0.18
jbig2dec (Alpine package) - update to 0.17-r1
jbig2dec - update to 0.12-5.el7
libjbig2dec0 (Ubuntu package) - update to 0.12+201509181ubuntu0.1+esm2
jbig2dec (Ubuntu package) - update to 0.12+201509181ubuntu0.1+esm2
jbig2dec (Red Hat package) - addressed in versions 0.14-4.el8_0, 0.14-4.el8_1, 0.14-4.el8_2

External References

Related Security Bulletins