First published: Wed Mar 10 2021(Updated: )
Libjpeg-turbo (versions 2.0.91 and 2.0.90) is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image. References: <a href="https://github.com/libjpeg-turbo/libjpeg-turbo/issues/493">https://github.com/libjpeg-turbo/libjpeg-turbo/issues/493</a> [<a href="https://github.com/libjpeg-turbo/libjpeg-turbo/issues/493">https://github.com/libjpeg-turbo/libjpeg-turbo/issues/493</a> <a href="https://github.com/libjpeg-turbo/libjpeg-turbo/commit/1719d12e51641cce5c77e259516649ba5ef6303c">https://github.com/libjpeg-turbo/libjpeg-turbo/commit/1719d12e51641cce5c77e259516649ba5ef6303c</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Libjpeg-turbo Libjpeg-turbo | =2.0.90 | |
Fedoraproject Fedora | =34 | |
redhat/libjpeg-turbo | <2.1 | 2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20205 is a vulnerability in Libjpeg-turbo versions 2.0.91 and 2.0.90 that can be exploited to cause a denial of service by triggering a divide by zero when processing a crafted GIF image.
CVE-2021-20205 has a severity score of 6.5 out of 10, which is considered medium severity.
Libjpeg-turbo versions 2.0.91 and 2.0.90 are affected by CVE-2021-20205.
CVE-2021-20205 can be exploited by processing a specially crafted GIF image, which triggers a divide by zero and leads to a denial of service.
You can find more information about CVE-2021-20205 in the following references: [Reference 1](https://bugzilla.redhat.com/show_bug.cgi?id=1937385), [Reference 2](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QMLEY6HLVZAGXIOGGPPUAMRJUA6LB3FD/), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TM3AHZEYGYFEDL6AW5RLEAJNVRWEJDFL/).