Search CVE reports
1 – 10 of 46 results
A heap-based buffer overflow issue was discovered in libjpeg-turbo in h2v2_merged_upsample_internal() function of jdmrgext.c file. The vulnerability can only be exploited with 12-bit data precision for which the range of the...
3 affected packages
libjpeg9, libjpeg-turbo, libjpeg6b
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg9 | — | Not affected | Not affected | Not affected |
libjpeg-turbo | — | Not affected | Not affected | Not affected |
libjpeg6b | — | Not affected | Not affected | Not affected |
libjpeg commit 281daa9 was discovered to contain a segmentation fault via LineMerger::GetNextLowpassLine at linemerger.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
4 affected packages
libjpeg, libjpeg-turbo, libjpeg6b, libjpeg9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |
libjpeg commit 281daa9 was discovered to contain a segmentation fault via HuffmanDecoder::Get at huffmandecoder.hpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
4 affected packages
libjpeg, libjpeg-turbo, libjpeg6b, libjpeg9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |
libjpeg commit 281daa9 was discovered to contain an infinite loop via the component Frame::ParseTrailer.
4 affected packages
libjpeg, libjpeg-turbo, libjpeg6b, libjpeg9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |
libjpeg commit 842c7ba was discovered to contain an infinite loop via the component JPEG::ReadInternal.
4 affected packages
libjpeg-turbo, libjpeg6b, libjpeg9, libjpeg
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |
libjpeg | Needs evaluation | Needs evaluation | Needs evaluation | Not in release |
There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.
4 affected packages
libjpeg, libjpeg9, libjpeg-turbo, libjpeg6b
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg | Needs evaluation | Needs evaluation | Needs evaluation | — |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
In libjpeg 1.63, there is a NULL pointer dereference in LineBuffer::FetchRegion in linebuffer.cpp.
4 affected packages
libjpeg, libjpeg-turbo, libjpeg6b, libjpeg9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg | Needs evaluation | Vulnerable | Vulnerable | — |
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |
In libjpeg 1.63, there is a NULL pointer dereference in Component::SubXOf in component.hpp.
4 affected packages
libjpeg, libjpeg-turbo, libjpeg6b, libjpeg9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg | Needs evaluation | Vulnerable | Vulnerable | — |
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |
libjpeg 1.63 has a heap-based buffer over-read in HierarchicalBitmapRequester::FetchRegion in hierarchicalbitmaprequester.cpp because the MCU size can be different between allocation and use.
4 affected packages
libjpeg, libjpeg-turbo, libjpeg6b, libjpeg9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg | Vulnerable | Vulnerable | Vulnerable | — |
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |
In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically...
4 affected packages
libjpeg, libjpeg-turbo, libjpeg6b, libjpeg9
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS |
---|---|---|---|---|
libjpeg | Needs evaluation | Needs evaluation | Needs evaluation | — |
libjpeg-turbo | Not affected | Not affected | Not affected | Not affected |
libjpeg6b | Not affected | Not affected | Not affected | Not affected |
libjpeg9 | Not affected | Not affected | Not affected | Not affected |