USN-5553-1: libjpeg-turbo vulnerabilities
It was discovered that libjpeg-turbo was not properly handling EOF characters, which could lead to excessive memory consumption through the execution of a large loop. An attacker could possibly use this issue to cause a denial of service. (CVE-2018-11813) It was discovered that libjpeg-turbo was not properly performing bounds check operations, which could lead to a heap-based buffer overread. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 ESM. (CVE-2018-14498) It was discovered that libjpeg-turbo was not properly limiting the amount of main memory being consumed by the system during decompression or multi-pass compression operations, which could lead to excessive memory consumption. An attacker could possibly use this issue to cause a denial of service. (CVE-2020-14152) It was discovered that libjpeg-turbo was not properly setting variable sizes when performing certain kinds of encoding operations, which could lead to a stack-based buffer overflow. If a user or automated system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. (CVE-2020-17541)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-5553-1.
What is the severity of USN-5553-1?
The severity of USN-5553-1 is not mentioned in the information provided.
Which software is affected by USN-5553-1?
The software affected by USN-5553-1 is libjpeg-turbo.
How can I fix the vulnerability in libjpeg-turbo?
To fix the vulnerability in libjpeg-turbo, update the affected software to version 1.4.2-0ubuntu3.4+esm1 (for Ubuntu 16.04) or version 1.3.0-0ubuntu2.1+esm2 (for Ubuntu 14.04).
Where can I find more information about USN-5553-1?
You can find more information about USN-5553-1 at the following references: [CVE-2020-17541](https://ubuntu.com/security/CVE-2020-17541), [CVE-2020-14152](https://ubuntu.com/security/CVE-2020-14152), [CVE-2018-14498](https://ubuntu.com/security/CVE-2018-14498).