libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in getrgbrow() in rdppm.c via a malformed PPM input file.
[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"279960956856796919083660656941318470986",
"339143231265080250257308579932503053796",
"131917594966023431801087663642952665251",
"156807076211336174187134914508724087246",
"333061502291305840284261457804340431451"
]
},
"target": {
"file": "rdppm.c"
},
"signature_type": "Line",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/libjpeg-turbo/libjpeg-turbo/commit/3de15e0c344d11d4b90f4a47136467053eb2d09a",
"id": "CVE-2020-13790-4163c7b5"
},
{
"digest": {
"function_hash": "100417613708608266563647517534113762204",
"length": 4668.0
},
"target": {
"function": "start_input_ppm",
"file": "rdppm.c"
},
"signature_type": "Function",
"deprecated": false,
"signature_version": "v1",
"source": "https://github.com/libjpeg-turbo/libjpeg-turbo/commit/3de15e0c344d11d4b90f4a47136467053eb2d09a",
"id": "CVE-2020-13790-ae5bae3c"
}
]