Total vulnerabilities in the database
get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
Software | From | Fixed in |
---|---|---|
mozilla / mozjpeg | - | 3.3.1.x |
libjpeg-turbo / libjpeg-turbo | - | 1.5.90.x |
fedoraproject / fedora | 28 | 28.x |
debian / debian_linux | 8.0 | 8.0.x |
opensuse / leap | 15.0 | 15.0.x |