MEDIUM
libjpeg-turbo: denial of service via specially-crafted JPEG file
Published Oct 10, 2017
6.5
MEDIUMCVSS 3.0
EPSS 3.23%
Description
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
Affected products
No data.
Configuration 1
- ≤ 1.2.90
Configuration 2
OR
- 20
- 21
Configuration 3
OR
- 12.04
- 14.04
- 14.10
No data.
Red Hat Enterprise Linux 6
libjpeg-turbo
Will not fix
Red Hat Enterprise Linux 7
libjpeg-turbo
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | libjpeg-turbo | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | libjpeg-turbo | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (14)
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147315.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147336.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/150957.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-March/150967.html vendor-advisoryx_refsource_FEDORAThird Party Advisory
- http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26482&sid=81658bc2f51a8d9893279cd01e83783f x_refsource_MISCThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/11/26/8 mailing-listx_refsource_MLISTMailing List
- http://www.securityfocus.com/bid/71326 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2014-9092 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1169845 x_refsource_CONFIRMIssue TrackingPatchThird Party AdvisoryVDB Entry
- https://nvd.nist.gov/vuln/detail/CVE-2014-9092
- https://tapani.tarvainen.info/linux/convertbug/ x_refsource_MISCThird Party Advisory
- https://usn.ubuntu.com/3706-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/3706-2/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2014-9092
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 10, 2017
Updated Aug 6, 2024
Reserved Nov 26, 2014
Link CVE-2014-9092
CISA Vulnrichment
Updated n/a