ALINUX2-SA-2019%3A0070
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2016-3616: The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file. CVE-2018-11212: An issue was discovered in libjpeg 9a. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file. CVE-2018-11213: An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file. CVE-2018-11214: An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file. CVE-2018-11813: libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF. CVE-2018-14498: get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | libjpeg-turbo |
Timeline
- Oct 9, 2019 CVE Published
- Oct 9, 2019 CVE Updated
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-3616 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-14498 advisory
- ALINUX2-SA-2019:0070: libjpeg-turbo security update (Moderate) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11212 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11213 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11214 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11813 advisory