Libjpeg-turbo all version have a stack-based buffer overflow in the "transform" component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
{
"binaries": [
{
"binary_name": "libjpeg-turbo-progs",
"binary_version": "1.3.0-0ubuntu2.1+esm2"
},
{
"binary_name": "libjpeg-turbo-test",
"binary_version": "1.3.0-0ubuntu2.1+esm2"
},
{
"binary_name": "libjpeg-turbo8",
"binary_version": "1.3.0-0ubuntu2.1+esm2"
},
{
"binary_name": "libjpeg-turbo8-dev",
"binary_version": "1.3.0-0ubuntu2.1+esm2"
},
{
"binary_name": "libturbojpeg",
"binary_version": "1.3.0-0ubuntu2.1+esm2"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_name": "libjpeg-turbo-progs",
"binary_version": "1.4.2-0ubuntu3.4+esm1"
},
{
"binary_name": "libjpeg-turbo-test",
"binary_version": "1.4.2-0ubuntu3.4+esm1"
},
{
"binary_name": "libjpeg-turbo8",
"binary_version": "1.4.2-0ubuntu3.4+esm1"
},
{
"binary_name": "libjpeg-turbo8-dev",
"binary_version": "1.4.2-0ubuntu3.4+esm1"
},
{
"binary_name": "libturbojpeg",
"binary_version": "1.4.2-0ubuntu3.4+esm1"
}
],
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"
}
{
"binaries": [
{
"binary_name": "libjpeg-turbo-progs",
"binary_version": "1.5.2-0ubuntu5.18.04.6"
},
{
"binary_name": "libjpeg-turbo-test",
"binary_version": "1.5.2-0ubuntu5.18.04.6"
},
{
"binary_name": "libjpeg-turbo8",
"binary_version": "1.5.2-0ubuntu5.18.04.6"
},
{
"binary_name": "libjpeg-turbo8-dev",
"binary_version": "1.5.2-0ubuntu5.18.04.6"
},
{
"binary_name": "libturbojpeg",
"binary_version": "1.5.2-0ubuntu5.18.04.6"
},
{
"binary_name": "libturbojpeg0-dev",
"binary_version": "1.5.2-0ubuntu5.18.04.6"
}
],
"availability": "No subscription required"
}
{
"binaries": [
{
"binary_name": "libjpeg-turbo-progs",
"binary_version": "2.0.3-0ubuntu1.20.04.3"
},
{
"binary_name": "libjpeg-turbo-test",
"binary_version": "2.0.3-0ubuntu1.20.04.3"
},
{
"binary_name": "libjpeg-turbo8",
"binary_version": "2.0.3-0ubuntu1.20.04.3"
},
{
"binary_name": "libjpeg-turbo8-dev",
"binary_version": "2.0.3-0ubuntu1.20.04.3"
},
{
"binary_name": "libturbojpeg",
"binary_version": "2.0.3-0ubuntu1.20.04.3"
},
{
"binary_name": "libturbojpeg0-dev",
"binary_version": "2.0.3-0ubuntu1.20.04.3"
}
],
"availability": "No subscription required"
}