CVE-2020-35538: Null Pointer Dereference
A crafted input file could cause a null pointer dereference in jcopysamplerows() when processed by libjpeg-turbo.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35538?
The severity of CVE-2020-35538 is medium with a severity value of 5.5.
What is CVE-2020-35538?
CVE-2020-35538 is a vulnerability that could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
Which software is affected by CVE-2020-35538?
The software affected by CVE-2020-35538 is libjpeg-turbo version 1:2.0.6-4, 1:2.1.5-2 (Debian), version 1.5.2-0ubuntu5.18.04.6 (Ubuntu Bionic), and version 2.0.3-0ubuntu1.20.04.3 (Ubuntu Focal).
How can I fix CVE-2020-35538?
To fix CVE-2020-35538, update libjpeg-turbo to the following versions: 1:2.0.6-4 or 1:2.1.5-2 (Debian), 1.5.2-0ubuntu5.18.04.6 (Ubuntu Bionic), or 2.0.3-0ubuntu1.20.04.3 (Ubuntu Focal).
Where can I find more information about CVE-2020-35538?
You can find more information about CVE-2020-35538 at the following references: [link1], [link2], [link3].