漏洞信息详情
libjpeg-turbo 安全漏洞
漏洞简介
libjpeg是一个包含JPEG解码以及JPEG编码等功能的C语言库。libjpeg-turbo是libjpeg的一个优化改进版本。
libjpeg-turbo 1.5.90版本中的jmemmgr.c文件中的‘allow_sarray’函数存在安全漏洞。攻击者可借助特制的BMP图像利用该漏洞造成拒绝服务(除零错误)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/43e84cff1bb2bd8293066f6ac4eb0df61ddddbc6
参考网址
来源:MISC
链接:https://www.tenable.com/security/research/tra-2018-17
来源:CONFIRM
链接:https://github.com/libjpeg-turbo/libjpeg-turbo/commit/43e84cff1bb2bd8293066f6ac4eb0df61ddddbc6
来源:UBUNTU
链接:https://usn.ubuntu.com/3706-1/
来源:UBUNTU
链接:https://usn.ubuntu.com/3706-2/
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.html
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2019/01/msg00015.html
来源:BID
链接:http://www.securityfocus.com/bid/104543
来源:MLIST
链接:https://lists.debian.org/debian-lts-announce/2020/07/msg00033.html
来源:BID
链接:https://www.securityfocus.com/bid/104543
来源:SUSE
链接:http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20190711-1.html
来源:www.suse.com
链接:https://www.suse.com/support/update/announcement/2019/suse-su-20191111-1.html
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79938
来源:www.ibm.com
链接:http://www.ibm.com/support/docview.wss?uid=ibm10874446
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/ESB-2020.2628/
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/79730
来源:www.auscert.org.au
链接:https://www.auscert.org.au/bulletins/77726
受影响实体
- Libjpeg-Turbo Libjpeg-Turbo:1.5.90<!--2000-1-1-->
补丁
- libjpeg-turbo 安全漏洞的修复措施<!--2018-6-19-->
还没有评论,来说两句吧...