Bugzilla – Full Text Bug Listing |
Summary: | VUL-0: CVE-2020-35538: libjpeg62-turbo,libjpeg-turbo: Null pointer dereference in jcopy_sample_rows() function | ||
---|---|---|---|
Product: | [Novell Products] SUSE Security Incidents | Reporter: | Hu <cathy.hu> |
Component: | Incidents | Assignee: | Security Team bot <security-team> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Normal | ||
Priority: | P3 - Medium | CC: | security-team, thomas.leroy |
Version: | unspecified | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/341088/ | ||
Whiteboard: | CVSSv3.1:SUSE:CVE-2020-35538:4.7:(AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H) | ||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Hu
2022-08-30 11:12:18 UTC
Affected: - SUSE:SLE-12:Update/libjpeg-turbo 1.5.3 - SUSE:SLE-12:Update/libjpeg62-turbo 1.5.3 - SUSE:SLE-15:Update/libjpeg-turbo 1.5.3 - SUSE:SLE-15:Update/libjpeg62-turbo 1.5.3 Not Affected (already fixed): - SUSE:SLE-15-SP4:Update/libjpeg-turbo 2.1.1 - SUSE:SLE-15-SP4:Update/libjpeg62-turbo 2.1.1 - openSUSE:Factory/libjpeg-turbo 2.1.4 - openSUSE:Factory/libjpeg62-turbo 2.1.4 Not affected (does not contain relevant code): - SUSE:SLE-11:Update/jpeg Submitted for 15,12/libjpeg-turbo. I believe all fixed. (In reply to Petr Gajdos from comment #2) > Submitted for 15,12/libjpeg-turbo. > > I believe all fixed. Thanks for your submissions Petr. Could you also please submit to: - SUSE:SLE-12:Update/libjpeg62-turbo 1.5.3 - SUSE:SLE-15:Update/libjpeg62-turbo 1.5.3 SUSE-SU-2022:3475-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1202915 CVE References: CVE-2020-35538 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): libjpeg-turbo-1.5.3-31.28.1, libjpeg62-turbo-1.5.3-31.28.1 SUSE Linux Enterprise Server 12-SP5 (src): libjpeg-turbo-1.5.3-31.28.1, libjpeg62-turbo-1.5.3-31.28.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. SUSE-SU-2022:3523-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1202915 CVE References: CVE-2020-35538 JIRA References: Sources used: openSUSE Leap Micro 5.2 (src): libjpeg-turbo-1.5.3-150000.32.5.1 openSUSE Leap 15.4 (src): libjpeg62-turbo-1.5.3-150000.32.5.1 openSUSE Leap 15.3 (src): libjpeg-turbo-1.5.3-150000.32.5.1, libjpeg62-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): libjpeg-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): libjpeg-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): libjpeg-turbo-1.5.3-150000.32.5.1, libjpeg62-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Micro 5.2 (src): libjpeg-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Micro 5.1 (src): libjpeg-turbo-1.5.3-150000.32.5.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination. done |