Out-of-bounds Write Affecting libjpeg-turbo-debugsource package, versions <0:2.0.90-6.el9_1
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-ROCKY9-LIBJPEGTURBODEBUGSOURCE-3357656
- published 9 Mar 2023
- disclosed 18 Jun 2022
Introduced: 18 Jun 2022
CVE-2021-46822 Open this link in a new tabHow to fix?
Upgrade Rocky-Linux:9
libjpeg-turbo-debugsource
to version 0:2.0.90-6.el9_1 or higher.
This issue was patched in RLSA-2023:1068
.
NVD Description
Note: Versions mentioned in the description apply only to the upstream libjpeg-turbo-debugsource
package and not the libjpeg-turbo-debugsource
package as distributed by Rocky-Linux
.
See How to fix?
for Rocky-Linux:9
relevant fixed versions and status.
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.