CVE-2020-14152: High severity suse libjpeg8 vulnerability
In IJG JPEG (aka libjpeg) before 9d, jpegmemavailable() in jmemnobs.c in djpeg does not honor the maxmemorytouse setting, possibly causing excessive memory consumption.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-14152.
What is the title of this vulnerability?
The title of this vulnerability is 'In IJG JPEG (aka libjpeg) before 9d jpeg_mem_available() in jmemnobs.c in djpeg does not honor the m…'
What is the severity level of CVE-2020-14152?
The severity level of CVE-2020-14152 is high with a CVSS score of 7.1.
Which software versions are affected by CVE-2020-14152?
The affected software versions include libjpeg-turbo 1:1.5.2-2+deb10u1, libjpeg-turbo 1:2.0.6-4, libjpeg-turbo 1:2.1.5-2, libjpeg9 1:9e-1, libjpeg-turbo 1.3.0-0ubuntu2.1+ (qualifiers: trusty), libjpeg-turbo 1:1.5.1-2+ to 1:1.5.2-2+ (qualifiers: upstream), libjpeg-turbo 1.4.2-0ubuntu3.4+ (qualifiers: xenial), libjpeg9 1:9 (qualifiers: xenial), libjpeg9 9 (qualifiers: upstream), libjpeg6b 6 (qualifiers: trusty), and libjpeg6b 1:6 (qualifiers: xenial).
How can I fix CVE-2020-14152?
To fix CVE-2020-14152, you should update your libjpeg or libjpeg-turbo package to the recommended versions provided by your respective operating system distribution.