Lucene search

K
ubuntuUbuntuUSN-5336-1
HistoryMar 23, 2022 - 12:00 a.m.

libjpeg9 vulnerabilities

2022-03-2300:00:00
ubuntu.com
63
ubuntu 16.04 esm
libjpeg9
cjpeg utility
denial of service
arbitrary code
cve-2016-3616
cve-2018-11212
cve-2018-11813
cve-2020-14152
cve-2020-14153
cve-2018-11213
cve-2018-11214

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

8.7

Confidence

High

EPSS

0.021

Percentile

89.3%

Releases

  • Ubuntu 16.04 ESM

Packages

  • libjpeg9 - Independent JPEG Group’s JPEG runtime library

Details

Aladdin Mubaied discovered that the cjpeg utility in libjpeg9 did not properly
validate the input image’s size. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2016-3616)

It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
certain input. An attacker could possibly use these issues to cause a denial of
service. (CVE-2018-11212, CVE-2018-11813, CVE-2020-14152, CVE-2020-14153)

It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
memory when supplied with certain input. An attacker could possibly use these
issues to cause a denial of service or execute arbitrary code.
(CVE-2018-11213, CVE-2018-11214)

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H

AI Score

8.7

Confidence

High

EPSS

0.021

Percentile

89.3%