First published: Fri Dec 21 2018(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Libjpeg-turbo Libjpeg-turbo | =2.0.1 | |
debian/libjpeg-turbo | 1:2.0.6-4 1:2.1.5-2 1:2.1.5-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20330 is a vulnerability in libjpeg-turbo 2.0.1 that allows an integer overflow leading to a heap-based buffer overflow when processing BMP images.
CVE-2018-20330 has a severity rating of 8.8, which is classified as high.
CVE-2018-20330 affects libjpeg-turbo 2.0.1 and potentially other versions as well.
For debian users, the recommended remedy for CVE-2018-20330 is to update to version 1:1.5.2-2+deb10u1, 1:2.0.6-4, or 1:2.1.5-2 of libjpeg-turbo.
For ubuntu users, the recommended remedy for CVE-2018-20330 is to update to version 2.0.1-0ubuntu2.2 (disco) or 2.0.2-0ubuntu1 (eoan) of libjpeg-turbo.