libjpeg-turbo 1.3.1

CPE Details

libjpeg-turbo 1.3.1
1.3.1
2019-06-14
15h52 +00:00
2019-06-14
15h52 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:1.3.1:*:*:*:*:*:*:*

Informations

Vendor

libjpeg-turbo

Product

libjpeg-turbo

Version

1.3.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-17541 2021-06-01 12h44 +00:00 Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
8.8
High
CVE-2018-14498 2019-03-07 21h00 +00:00 get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
6.5
Medium