CVE-2020-13790: High severity libjpeg-turbo-devel vulnerability
libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in getrgbrow() in rdppm.c via a malformed PPM input file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-13790?
CVE-2020-13790 is a vulnerability found in libjpeg-turbo 2.0.4 and mozjpeg 4.0.0, which allows a heap-based buffer over-read in the 'get_rgb_row()' function in rdppm.c through a malformed PPM input file.
Which software versions are affected by CVE-2020-13790?
The affected software versions include libjpeg-turbo 2.0.4 and mozjpeg 4.0.0.
What is the severity of CVE-2020-13790?
CVE-2020-13790 has a severity rating of 8.1 (High).
How can I fix the vulnerability CVE-2020-13790?
To fix the vulnerability, you should update libjpeg-turbo to version 1.5.2-0ubuntu5.18.04.4, or a higher version if available.
Where can I find more information about CVE-2020-13790?
You can find more information about CVE-2020-13790 at the following references: [reference 1](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00031.html), [reference 2](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00062.html), [reference 3](https://github.com/libjpeg-turbo/libjpeg-turbo/commit/3de15e0c344d11d4b90f4a47136467053eb2d09a).