libjpeg-turbo 1.5.0

CPE Details

libjpeg-turbo 1.5.0
1.5.0
2019-06-14
15h52 +00:00
2019-06-14
15h52 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:1.5.0:*:*:*:*:*:*:*

Informations

Vendor

libjpeg-turbo

Product

libjpeg-turbo

Version

1.5.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2020-17541 2021-06-01 12h44 +00:00 Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
8.8
Haute
CVE-2018-14498 2019-03-07 21h00 +00:00 get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
6.5
Moyen