CVE-2020-17541: Buffer Overflow
Last updated 24 July 2024
Other sources
Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-17541?
CVE-2020-17541 is a vulnerability in Libjpeg-turbo that allows a remote attacker to execute arbitrary code or cause a denial of service by sending a malformed jpeg file.
How severe is CVE-2020-17541?
CVE-2020-17541 has a severity score of 8.8 (high).
Which versions of Libjpeg-turbo are affected by CVE-2020-17541?
Versions 1:2.0.6-4, 1:2.1.5-2, 1:1.5.2-2+deb10u1, 1.5.2-0ubuntu5.18.04.6, 2.0.3-0ubuntu1.20.04.3, 1.3.0-0ubuntu2.1+, 1:2.0.5-1, 1.4.2-0ubuntu3.4+, and Libjpeg-turbo version up to 2.0.4 are affected by CVE-2020-17541.
How can I fix CVE-2020-17541?
To fix CVE-2020-17541, update Libjpeg-turbo to a version that includes the fix, such as versions 1:2.0.6-4 or 1:2.1.5-2.
Where can I find more information about CVE-2020-17541?
You can find more information about CVE-2020-17541 in the references: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/392, https://cwe.mitre.org/data/definitions/121.html, and https://launchpad.net/bugs/cve/CVE-2020-17541.