PublicDateAtUSN: 2020-06-03 19:15:00 UTC Candidate: CVE-2020-13790 PublicDate: 2020-06-03 19:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13790 https://ubuntu.com/security/notices/USN-4386-1 Description: libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file. Ubuntu-Description: Notes: Mitigation: Bugs: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/433 Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H [8.1 HIGH] Patches_libjpeg-turbo: upstream: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/3de15e0c344d11d4b90f4a47136467053eb2d09a upstream_libjpeg-turbo: needs-triage precise/esm_libjpeg-turbo: released (1.1.90+svn733-0ubuntu4.6) trusty_libjpeg-turbo: ignored (out of standard support) trusty/esm_libjpeg-turbo: released (1.3.0-0ubuntu2.1+esm1) xenial_libjpeg-turbo: released (1.4.2-0ubuntu3.4) esm-infra/xenial_libjpeg-turbo: released (1.4.2-0ubuntu3.4) bionic_libjpeg-turbo: released (1.5.2-0ubuntu5.18.04.4) eoan_libjpeg-turbo: released (2.0.3-0ubuntu1.19.10.1) focal_libjpeg-turbo: released (2.0.3-0ubuntu1.20.04.1) devel_libjpeg-turbo: released (2.0.3-0ubuntu2)