PublicDateAtUSN: 2018-11-29 08:29:00 UTC Candidate: CVE-2018-19664 PublicDate: 2018-11-29 08:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-19664 https://ubuntu.com/security/notices/USN-4190-1 Description: libjpeg-turbo 2.0.1 has a heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg. Ubuntu-Description: Notes: mdeslaur> introduced by: mdeslaur> https://github.com/libjpeg-turbo/libjpeg-turbo/commit/aa7459050d7a50e1d8a99488902d41fbc118a50f Bugs: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/305 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_libjpeg-turbo: upstream: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f8cca819a4fb42aafa5f70df43c45e8c416d716f upstream_libjpeg-turbo: needs-triage precise/esm_libjpeg-turbo: not-affected trusty_libjpeg-turbo: not-affected (1.3.0-0ubuntu2.1) trusty/esm_libjpeg-turbo: not-affected (1.3.0-0ubuntu2.1) xenial_libjpeg-turbo: not-affected (1.4.2-0ubuntu3.1) esm-infra/xenial_libjpeg-turbo: not-affected (1.4.2-0ubuntu3.1) bionic_libjpeg-turbo: not-affected (1.5.2-0ubuntu5.18.04.1) cosmic_libjpeg-turbo: ignored (reached end-of-life) disco_libjpeg-turbo: released (2.0.1-0ubuntu2.2) eoan_libjpeg-turbo: released (2.0.2-0ubuntu1) devel_libjpeg-turbo: released (2.0.2-0ubuntu1)