First published: Thu Nov 29 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libjpeg-turbo Libjpeg-turbo | =2.0.1 | |
debian/libjpeg-turbo | 1:2.0.6-4 1:2.1.5-2 1:2.1.5-3 |
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f8cca819a4fb42aafa5f70df43c45e8c416d716f
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19664 is a vulnerability in libjpeg-turbo 2.0.1 that allows a heap-based buffer over-read.
CVE-2018-19664 affects libjpeg-turbo 2.0.1 and can lead to a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c.
CVE-2018-19664 has a severity rating of 6.5, which is considered medium.
To fix CVE-2018-19664 in libjpeg-turbo 2.0.1, you should update to a version that includes the fix, such as 2.0.2-0ubuntu1 on Ubuntu or apply the appropriate security patches provided by the software vendor.
You can find more information about CVE-2018-19664 on the GitHub page for libjpeg-turbo, the Ubuntu Security Notice, and the launchpad.net bug page.