You are here
Home > Preporuke > Sigurnosni nedostaci programske biblioteke libjpeg-turbo

Sigurnosni nedostaci programske biblioteke libjpeg-turbo

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-3706-1
July 09, 2018

libjpeg-turbo vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 18.04 LTS
– Ubuntu 17.10
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS

Summary:

libjpeg-turbo could be made to crash or run programs as your login if it
opened a specially crafted file.

Software Description:
– libjpeg-turbo: library for handling JPEG files

Details:

It was discovered that libjpeg-turbo incorrectly handled certain malformed
JPEG images. If a user or automated system were tricked into opening a
specially crafted JPEG image, a remote attacker could cause libjpeg-turbo
to crash, resulting in a denial of service, or possibly execute arbitrary
code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
libjpeg-turbo8 1.5.2-0ubuntu5.18.04.1

Ubuntu 17.10:
libjpeg-turbo8 1.5.2-0ubuntu5.17.10.1

Ubuntu 16.04 LTS:
libjpeg-turbo8 1.4.2-0ubuntu3.1

Ubuntu 14.04 LTS:
libjpeg-turbo8 1.3.0-0ubuntu2.1

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/usn/usn-3706-1
CVE-2014-9092, CVE-2016-3616, CVE-2017-15232, CVE-2018-11212,
CVE-2018-11213, CVE-2018-11214, CVE-2018-1152

Package Information:
https://launchpad.net/ubuntu/+source/libjpeg-turbo/1.5.2-0ubuntu5.18.04.1
https://launchpad.net/ubuntu/+source/libjpeg-turbo/1.5.2-0ubuntu5.17.10.1
https://launchpad.net/ubuntu/+source/libjpeg-turbo/1.4.2-0ubuntu3.1
https://launchpad.net/ubuntu/+source/libjpeg-turbo/1.3.0-0ubuntu2.1

—–BEGIN PGP SIGNATURE—–

iQIzBAEBCgAdFiEEUMSg3c8x5FLOsZtRZWnYVadEvpMFAltDpxgACgkQZWnYVadE
vpMcTQ//aJlwKxVAIj+vwGn9vNPlXAoUkoV3NbtGSCj4jXQFr7TN3cdmPxvoHLBQ
gVPuFUMrBwEAFTR8qSE2RMbaMcHNJQedN6fQB2raboWkPs2bSWm4HAQU9LWcfwad
0nu8xCUbJpSv3Wafxxd2ekY4dkul+Jpe+ezjOwtAlDnSkTvn+79NEbqATIcRrAKT
PWzwc9QmM76o7NK4XvtJB2wMefG9kSfoEEcTAzy6xlrRb0Ej0F8AB46gCgK+hixh
DfxBvOaVCarlzQQdqBlH4VCd16MNZt5Eil13CHmyHG/TJvlLqjT821ceZ+lkOXzZ
9ailR1BUm9WwiFm4vPcuF14JfamgJmSLm7eoASTzmW3sJ4fJbOMNc20S0j/ZABzt
dOWEptHazrkFcgOFfNpwCcVglVYHtrgkkigJeJTDXpFYQRCEaTFkBbpV8kOQ4mUy
6fl+iTI/5KnkqW6zHVnEA/XCnXH5vHyiqEs7JFfxIlapt83SLrjqBfqzTp0+iETL
hG/qE8sDr1jRiWqlIN6hTtVIqCZDVodjmPMp+zeBFNIsabRnODUXlMq9GQ02soXo
VlrjNvBm27UhJoN3q7LvDm2DG2DTqjALPybH/fS+8YvoVyZSVGocT4dryxO7WArb
ViV0CkOQFMbXvgjkuJW1Vzt4FBQCtAVI8PtRd5Lxl+qxghrRiwM=
=7Tbu
—–END PGP SIGNATURE—–

==========================================================================
Ubuntu Security Notice USN-3706-2
July 10, 2018

libjpeg-turbo vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 12.04 ESM

Summary:

libjpeg-turbo could be made to crash or run programs as your login if
it opened a specially crafted file.

Software Description:
– libjpeg-turbo: library for handling JPEG files

Details:

USN-3706-1 fixed a vulnerability in libjpeg-turbo. This update provides
the corresponding update for Ubuntu 12.04 ESM.

Original advisory details:

It was discovered that libjpeg-turbo incorrectly handled certain
malformed JPEG images. If a user or automated system were tricked into
opening a specially crafted JPEG image, a remote attacker could cause
libjpeg-turbo to crash, resulting in a denial of service, or possibly
execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 ESM:
libjpeg-turbo8                  1.1.90+svn733-0ubuntu4.5

In general, a standard system update will make all the necessary
changes.

References:
https://usn.ubuntu.com/usn/usn-3706-2
https://usn.ubuntu.com/usn/usn-3706-1
CVE-2014-9092, CVE-2016-3616, CVE-2018-11212, CVE-2018-11213,
CVE-2018-11214, CVE-2018-1152—–BEGIN PGP SIGNATURE—–
Version: GnuPG v2

iQIcBAABCAAGBQJbRLgkAAoJEEW851uECx9pNtAQAI8/1jx83cj7JcJz8JXuBd9T
EQJ5iSZpmjU4CHNU4eMrXvydQsWAdZnqh8cVQHDnHulkXKsOsgnM9HBt6YwDx6MX
Z7yWIU2DaffuPT8qo0OKP7yS1oeYoXZs3uGmZo5r99jzqBdK0cL7gTAa83q3EuIW
egz1pWfp17T7gXl1jAbBoXNMHv+e4nNWDccjMrLzjsFuu0bfPVAu70VRCc2Isz0g
GRJsAwpYDaGbeZstTUSv/dlay2y2wFvfZUndbuxoCtZfGGhvyVg0xt+Np2B6GruV
9Bc1//a29n/V5uo1Ip+Rrau7NCryzHoqkpqVF7Nhi0Kbgt4Iq1hJ+yyB2aIXG6Xd
X0qLKOUdDIe+5Ov0BaWWj09qgAdB66SJuPWwbh/3Cei8YOO0YzBYg0GGdfywcNg9
5hMhpubmva6dzjGCV4yeO+jcepJW8T0rWj3OWf9lX6fQsLPvGLMW5QSnoxwEHAcb
o2hDjcElbai9gDtzjZj2peecMooHiVXcPYjb4O+AfRTR1r8kFwaAPfitjSdtmHhr
vPuz/ieMV3yf/mdIHv2k2yAGWHjS0CANKwIook4w+iG/E+xv5O5F+SvSwcNw6pfU
3ryriXDPrD9c8mLxfq8CuX+HPzG21ek6vMfxyvvEQbrt6HDXE1wA9JW3+PuEMnjW
JAOpiRcLziRN7TYVF3qs
=qeDM
—–END PGP SIGNATURE—–

AutorZvonimir Bosnjak
Cert idNCERT-REF-2018-07-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top