Bugzilla – Bug 1202915
VUL-0: CVE-2020-35538: libjpeg62-turbo,libjpeg-turbo: Null pointer dereference in jcopy_sample_rows() function
Last modified: 2022-12-20 11:22:32 UTC
rh#2122387 A crafted input file could cause a null pointer dereference in jcopy_sample_rows() when processed by libjpeg-turbo. Upstream issue: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/441 Upstream fix: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/9120a247436e84c0b4eea828cb11e8f665fcde30 References: https://bugzilla.redhat.com/show_bug.cgi?id=2122387 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-35538
Affected: - SUSE:SLE-12:Update/libjpeg-turbo 1.5.3 - SUSE:SLE-12:Update/libjpeg62-turbo 1.5.3 - SUSE:SLE-15:Update/libjpeg-turbo 1.5.3 - SUSE:SLE-15:Update/libjpeg62-turbo 1.5.3 Not Affected (already fixed): - SUSE:SLE-15-SP4:Update/libjpeg-turbo 2.1.1 - SUSE:SLE-15-SP4:Update/libjpeg62-turbo 2.1.1 - openSUSE:Factory/libjpeg-turbo 2.1.4 - openSUSE:Factory/libjpeg62-turbo 2.1.4 Not affected (does not contain relevant code): - SUSE:SLE-11:Update/jpeg
Submitted for 15,12/libjpeg-turbo. I believe all fixed.
(In reply to Petr Gajdos from comment #2) > Submitted for 15,12/libjpeg-turbo. > > I believe all fixed. Thanks for your submissions Petr. Could you also please submit to: - SUSE:SLE-12:Update/libjpeg62-turbo 1.5.3 - SUSE:SLE-15:Update/libjpeg62-turbo 1.5.3
SUSE-SU-2022:3475-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1202915 CVE References: CVE-2020-35538 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): libjpeg-turbo-1.5.3-31.28.1, libjpeg62-turbo-1.5.3-31.28.1 SUSE Linux Enterprise Server 12-SP5 (src): libjpeg-turbo-1.5.3-31.28.1, libjpeg62-turbo-1.5.3-31.28.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2022:3523-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1202915 CVE References: CVE-2020-35538 JIRA References: Sources used: openSUSE Leap Micro 5.2 (src): libjpeg-turbo-1.5.3-150000.32.5.1 openSUSE Leap 15.4 (src): libjpeg62-turbo-1.5.3-150000.32.5.1 openSUSE Leap 15.3 (src): libjpeg-turbo-1.5.3-150000.32.5.1, libjpeg62-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (src): libjpeg-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Module for Desktop Applications 15-SP3 (src): libjpeg-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Module for Basesystem 15-SP3 (src): libjpeg-turbo-1.5.3-150000.32.5.1, libjpeg62-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Micro 5.2 (src): libjpeg-turbo-1.5.3-150000.32.5.1 SUSE Linux Enterprise Micro 5.1 (src): libjpeg-turbo-1.5.3-150000.32.5.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done