Bug 1588803 (CVE-2018-11813) - CVE-2018-11813 libjpeg: "cjpeg" utility large loop because read_pixel in rdtarga.c mishandles EOF
Summary: CVE-2018-11813 libjpeg: "cjpeg" utility large loop because read_pixel in rdta...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-11813
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: CVE-2020-14151 (view as bug list)
Depends On: 1588804 1588806 1588807 1588808 1591203
Blocks: 1588809 1849034
TreeView+ depends on / blocked
 
Reported: 2018-06-07 21:18 UTC by Pedro Sampaio
Modified: 2023-10-06 17:49 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-08-06 19:19:00 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2019:2052 0 None None None 2019-08-06 12:08:13 UTC

Description Pedro Sampaio 2018-06-07 21:18:50 UTC
libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.

References:

https://github.com/ChijinZ/security_advisories/blob/master/libjpeg-v9c/mail.pdf
https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9c

Comment 1 Pedro Sampaio 2018-06-07 21:19:13 UTC
Created libjpeg-turbo tracking bugs for this issue:

Affects: fedora-all [bug 1588804]

Comment 2 Pedro Sampaio 2018-06-07 21:20:38 UTC
Created mingw-libjpeg-turbo tracking bugs for this issue:

Affects: epel-7 [bug 1588806]
Affects: fedora-all [bug 1588808]

Comment 4 Stefan Cornelius 2018-06-14 09:07:54 UTC
Patch (libjpeg-turbo):
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/909a8cfc7bca9b2e6707425bdb74da997e8fa499

The following section in the upstream changelog entry is noteworthy:
"[...] Because this issue only affected cjpeg and not the underlying library, and because it did not involve any out-of-bounds reads or other exploitable behaviors, it was not believed to represent a security threat."

Comment 6 Stefan Cornelius 2018-06-14 09:31:38 UTC
Statement:

This issue affects the versions of libjpeg as shipped with Red Hat Enterprise Linux 4 and 5. This issue affects the versions of libjpeg-turbe as shipped with Red Hat Enterprise Linux 6 and 7. However, the problem is limited to the "cjpeg" utility and does not affect the library itself.

Comment 8 errata-xmlrpc 2019-08-06 12:08:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2019:2052 https://access.redhat.com/errata/RHSA-2019:2052

Comment 9 Product Security DevOps Team 2019-08-06 19:19:00 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2018-11813

Comment 10 Doran Moppert 2020-08-07 00:32:06 UTC
*** Bug 1849031 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.