Bugzilla – Bug 1183362
VUL-0: CVE-2021-20205: libjpeg-turbo: DoS via open crafted GIF
Last modified: 2021-03-11 09:36:53 UTC
rh#1937385 Libjpeg-turbo (versions 2.0.91 and 2.0.90) is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image. References: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/493 [https://github.com/libjpeg-turbo/libjpeg-turbo/issues/493 https://github.com/libjpeg-turbo/libjpeg-turbo/commit/1719d12e51641cce5c77e259516649ba5ef6303c References: https://bugzilla.redhat.com/show_bug.cgi?id=1937385 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-20205 https://access.redhat.com/security/cve/CVE-2021-20205 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20205
SLE and openSUSE are on libjpeg-turbo version 1.5.3 and even Factory is just on version 2.0.6. Closing this bug.