Security Fix(es):
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the getwordrgb_row function in rdppm.c.(CVE-2021-46822)
{ "severity": "Medium" }
{ "src": [ "libjpeg-turbo-2.0.5-2.oe1.src.rpm" ], "noarch": [ "libjpeg-turbo-help-2.0.5-2.oe1.noarch.rpm" ], "x86_64": [ "libjpeg-turbo-debugsource-2.0.5-2.oe1.x86_64.rpm", "libjpeg-turbo-devel-2.0.5-2.oe1.x86_64.rpm", "libjpeg-turbo-2.0.5-2.oe1.x86_64.rpm", "libjpeg-turbo-debuginfo-2.0.5-2.oe1.x86_64.rpm" ], "aarch64": [ "libjpeg-turbo-devel-2.0.5-2.oe1.aarch64.rpm", "libjpeg-turbo-debugsource-2.0.5-2.oe1.aarch64.rpm", "libjpeg-turbo-2.0.5-2.oe1.aarch64.rpm", "libjpeg-turbo-debuginfo-2.0.5-2.oe1.aarch64.rpm" ] }
{ "src": [ "libjpeg-turbo-2.0.5-2.oe1.src.rpm" ], "noarch": [ "libjpeg-turbo-help-2.0.5-2.oe1.noarch.rpm" ], "x86_64": [ "libjpeg-turbo-devel-2.0.5-2.oe1.x86_64.rpm", "libjpeg-turbo-debuginfo-2.0.5-2.oe1.x86_64.rpm", "libjpeg-turbo-debugsource-2.0.5-2.oe1.x86_64.rpm", "libjpeg-turbo-2.0.5-2.oe1.x86_64.rpm" ], "aarch64": [ "libjpeg-turbo-devel-2.0.5-2.oe1.aarch64.rpm", "libjpeg-turbo-debugsource-2.0.5-2.oe1.aarch64.rpm", "libjpeg-turbo-debuginfo-2.0.5-2.oe1.aarch64.rpm", "libjpeg-turbo-2.0.5-2.oe1.aarch64.rpm" ] }