First published: Wed Aug 31 2022(Updated: )
A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libjpeg-turbo Libjpeg-turbo | =2.0.5 | |
debian/libjpeg-turbo | 1:2.0.6-4 1:2.1.5-2 1:2.1.5-3 |
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9120a247436e84c0b4eea828cb11e8f665fcde30
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-35538 is medium with a severity value of 5.5.
CVE-2020-35538 is a vulnerability that could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo.
The software affected by CVE-2020-35538 is libjpeg-turbo version 1:2.0.6-4, 1:2.1.5-2 (Debian), version 1.5.2-0ubuntu5.18.04.6 (Ubuntu Bionic), and version 2.0.3-0ubuntu1.20.04.3 (Ubuntu Focal).
To fix CVE-2020-35538, update libjpeg-turbo to the following versions: 1:2.0.6-4 or 1:2.1.5-2 (Debian), 1.5.2-0ubuntu5.18.04.6 (Ubuntu Bionic), or 2.0.3-0ubuntu1.20.04.3 (Ubuntu Focal).
You can find more information about CVE-2020-35538 at the following references: [link1], [link2], [link3].