[Git][security-tracker-team/security-tracker][master] Add CVE-2020-17541/libjpeg-turbo

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jun 1 21:35:27 BST 2021



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8adc2466 by Salvatore Bonaccorso at 2021-06-01T22:35:00+02:00
Add CVE-2020-17541/libjpeg-turbo

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -66838,7 +66838,9 @@ CVE-2020-17543
 CVE-2020-17542 (Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to ...)
 	NOT-FOR-US: dotCMS
 CVE-2020-17541 (Libjpeg-turbo all version have a stack-based buffer overflow in the "t ...)
-	TODO: check
+	- libjpeg-turbo 1:2.0.5-1 (unimportant)
+	NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/c76f4a08263b0cea40d2967560ac7c21f6959079
+	NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/392
 CVE-2020-17540
 	RESERVED
 CVE-2020-17539



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8adc2466c4b8fa360d7f48b8fb1aa017c73e3872

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8adc2466c4b8fa360d7f48b8fb1aa017c73e3872
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210601/cff5aac8/attachment.htm>


More information about the debian-security-tracker-commits mailing list