PublicDateAtUSN: 2018-05-16
Candidate: CVE-2018-11212
PublicDate: 2018-05-16 17:29:00 UTC
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-11212
 https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9a
 https://ubuntu.com/security/notices/USN-3706-1
 https://ubuntu.com/security/notices/USN-3706-2
Description:
 An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in
 jmemmgr.c allows remote attackers to cause a denial of service
 (divide-by-zero error) via a crafted file.
Ubuntu-Description:
Notes:
 jdstrand> libjpeg-turbo is a fork of libjpeg8
Bugs:
 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=902176
Priority: low
Discovered-by:
Assigned-to: mdeslaur
CVSS:
 nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM]

Patches_libjpeg6b:
upstream_libjpeg6b: needs-triage
precise/esm_libjpeg6b: DNE
trusty_libjpeg6b: ignored (out of standard support)
trusty/esm_libjpeg6b: needed
xenial_libjpeg6b: ignored (end of standard support, was needed)
artful_libjpeg6b: ignored (reached end-of-life)
bionic_libjpeg6b: needed
cosmic_libjpeg6b: ignored (reached end-of-life)
disco_libjpeg6b: ignored (reached end-of-life)
eoan_libjpeg6b: ignored (reached end-of-life)
focal_libjpeg6b: needed
groovy_libjpeg6b: ignored (reached end-of-life)
hirsute_libjpeg6b: ignored (reached end-of-life)
impish_libjpeg6b: needed
jammy_libjpeg6b: needed
devel_libjpeg6b: needed

Patches_libjpeg-turbo:
 upstream: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/82923eb93a2eacf4a593e00e3e672bbb86a8a3a0
upstream_libjpeg-turbo: needs-triage
precise/esm_libjpeg-turbo: released (1.1.90+svn733-0ubuntu4.5)
trusty_libjpeg-turbo: released (1.3.0-0ubuntu2.1)
trusty/esm_libjpeg-turbo: released (1.3.0-0ubuntu2.1)
xenial_libjpeg-turbo: not-affected (1.4.2-0ubuntu3)
esm-infra/xenial_libjpeg-turbo: not-affected (1.4.2-0ubuntu3)
artful_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
bionic_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
cosmic_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
disco_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
eoan_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
focal_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
groovy_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
hirsute_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
impish_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
jammy_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)
devel_libjpeg-turbo: not-affected (1.5.2-0ubuntu5)

Patches_libjpeg9:
upstream_libjpeg9: needs-triage
precise/esm_libjpeg9: DNE
trusty_libjpeg9: DNE
trusty/esm_libjpeg9: DNE
xenial_libjpeg9: ignored (end of standard support, was needed)
artful_libjpeg9: ignored (reached end-of-life)
bionic_libjpeg9: needed
cosmic_libjpeg9: ignored (reached end-of-life)
disco_libjpeg9: not-affected (1:9c-2)
eoan_libjpeg9: not-affected (1:9c-2)
focal_libjpeg9: not-affected (1:9c-2)
groovy_libjpeg9: not-affected (1:9c-2)
hirsute_libjpeg9: not-affected (1:9c-2)
impish_libjpeg9: not-affected (1:9c-2)
jammy_libjpeg9: not-affected (1:9c-2)
devel_libjpeg9: not-affected (1:9c-2)
