Vulnerability Name:

CVE-2020-14152 (CCN-183463)

Assigned:2020-06-11
Published:2020-06-11
Updated:2023-02-27
Summary:IJG JPEG is vulnerable to a denial of service, caused by excessive memory consumption in jpeg_mem_available() in jmemnobs.c in djpeg. By persuading a victim to open a specially crafted file, a remote attacker could exploit this vulnerability to disclose information or cause the application to crash.
CVSS v3 Severity:7.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
6.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): High
4.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L)
3.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
3.2 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:P/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): Partial
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2020-14152

Source: cve@mitre.org
Type: Product
cve@mitre.org

Source: CCN
Type: Gentoo's Bugzilla – Bug 727908
(CVE-2020-14151, CVE-2020-14152, CVE-2020-14153) -

Source: cve@mitre.org
Type: Issue Tracking, Third Party Advisory
cve@mitre.org

Source: XF
Type: UNKNOWN
ijgjpeg-cve202014152-dos(183463)

Source: CCN
Type: Gentoo Repository
jpeg\media-libs - repo/gentoo.git - Official Gentoo ebuild repository

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2020-14152

Oval Definitions
Definition IDClassTitleLast Modified
oval:org.opensuse.security:def:202014152
V
CVE-2020-14152
2022-05-20
oval:org.opensuse.security:def:33795
P
Security update for apache2 (Important)
2022-01-12
oval:org.opensuse.security:def:33052
P
Security update for openexr (Moderate)
2021-12-01
oval:org.opensuse.security:def:30154
P
Security update for xen (Moderate)
2021-11-29
oval:org.opensuse.security:def:30258
P
Security update for strongswan (Important)
2021-10-19
oval:org.opensuse.security:def:32995
P
Security update for file (Important)
2021-09-02
oval:org.opensuse.security:def:33948
P
Security update for linuxptp (Important)
2021-07-21
oval:org.opensuse.security:def:30209
P
Security update for spice-gtk (Important)
2021-06-08
oval:org.opensuse.security:def:33659
P
Security update for libwebp (Critical)
2021-06-02
oval:org.opensuse.security:def:34409
P
Security update for qemu (Important)
2021-04-16
oval:org.opensuse.security:def:33891
P
Security update for xorg-x11-server (Important)
2021-04-13
oval:org.opensuse.security:def:30001
P
Security update for fwupdate (Important)
2021-04-09
oval:org.opensuse.security:def:33101
P
Security update for nghttp2 (Important)
2021-03-24
oval:org.opensuse.security:def:28955
P
Security update for the Linux Kernel (Live Patch 38 for SLE 12 SP2) (Important)
2021-03-17
oval:org.opensuse.security:def:34037
P
Security update for the Linux Kernel (Important)
2021-03-09
oval:org.opensuse.security:def:32839
P
Security update for cyrus-sasl (Important)
2020-12-28
oval:org.opensuse.security:def:33884
P
Security update for xen (Moderate)
2020-12-22
oval:org.opensuse.security:def:34340
P
Security update for MozillaFirefox (Critical)
2020-12-21
oval:org.opensuse.security:def:28662
P
Security update for finch
2020-12-01
oval:org.opensuse.security:def:29158
P
Security update for libvirt (Important)
2020-12-01
oval:org.opensuse.security:def:29639
P
Security update for cpio (Moderate)
2020-12-01
oval:org.opensuse.security:def:30297
P
Security update for strongswan (Moderate)
2020-12-01
oval:org.opensuse.security:def:32377
P
Security update for tiff (Moderate)
2020-12-01
oval:org.opensuse.security:def:35087
P
Security update for jpeg (Moderate)
2020-12-01
oval:org.opensuse.security:def:28719
P
Security update for kdebase4-workspace (Moderate)
2020-12-01
oval:org.opensuse.security:def:29796
P
Security update for hplip
2020-12-01
oval:org.opensuse.security:def:29771
P
Security update for glibc (Moderate)
2020-12-01
oval:org.opensuse.security:def:30316
P
Security update for tgt
2020-12-01
oval:org.opensuse.security:def:32388
P
Security update for tomcat6 (Important)
2020-12-01
oval:org.opensuse.security:def:33564
P
Security update for ImageMagick (Moderate)
2020-12-01
oval:org.opensuse.security:def:34194
P
Security update for pam_pkcs11 (Moderate)
2020-12-01
oval:org.opensuse.security:def:28803
P
Security update for openssl-certs
2020-12-01
oval:org.opensuse.security:def:29832
P
Security update for jpeg (Moderate)
2020-12-01
oval:org.opensuse.security:def:29858
P
Security update for Linux Kernel
2020-12-01
oval:org.opensuse.security:def:30360
P
Security update for wget (Moderate)
2020-12-01
oval:org.opensuse.security:def:32466
P
Security update for xorg-x11-libs (Moderate)
2020-12-01
oval:org.opensuse.security:def:33140
P
libarchive2 on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:33565
P
Security update for ImageMagick (Moderate)
2020-12-01
oval:org.opensuse.security:def:34252
P
Security update for postgresql10 (Important)
2020-12-01
oval:org.opensuse.security:def:28366
P
Security update for ppp (Moderate)
2020-12-01
oval:org.opensuse.security:def:29915
P
Security update for libcgroup1 (Moderate)
2020-12-01
oval:org.opensuse.security:def:30998
P
Security update for jasper (Low)
2020-12-01
oval:org.opensuse.security:def:32601
P
rsync on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:33163
P
libmysql55client18-32bit on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:33576
P
Security update for Mesa (Moderate)
2020-12-01
oval:org.opensuse.security:def:34301
P
Recommended update for python 2.7 (Moderate)
2020-12-01
oval:org.opensuse.security:def:28367
P
Security update for python (Moderate)
2020-12-01
oval:org.opensuse.security:def:29009
P
Security update for gnutls (Moderate)
2020-12-01
oval:org.opensuse.security:def:31035
P
Security update for jpeg (Moderate)
2020-12-01
oval:org.opensuse.security:def:32695
P
krb5-doc on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:33207
P
mozilla-nspr-32bit on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:28378
P
Security update for quagga (Important)
2020-12-01
oval:org.opensuse.security:def:29058
P
Security update for bind (Important)
2020-12-01
oval:org.opensuse.security:def:29554
P
Security update for MozillaFirefox (Important)
2020-12-01
oval:org.opensuse.security:def:32752
P
nagios on GA media (Moderate)
2020-12-01
oval:org.opensuse.security:def:33845
P
Security update for gtk2 (Moderate)
2020-12-01
oval:org.opensuse.security:def:34365
P
Security update for tcpdump (Important)
2020-12-01
oval:org.opensuse.security:def:28446
P
Security update for xen (Important)
2020-12-01
oval:org.opensuse.security:def:29097
P
Security update for glibc (Important)
2020-12-01
oval:org.opensuse.security:def:29555
P
Security update for MozillaFirefox (Important)
2020-12-01
oval:org.opensuse.security:def:28577
P
Security update for pcp
2020-12-01
oval:org.opensuse.security:def:29114
P
Security update for java-1_7_0-ibm (Important)
2020-12-01
oval:org.opensuse.security:def:29566
P
Security update for OpenEXR (Moderate)
2020-12-01
oval:org.opensuse.security:def:32376
P
Security update for tiff (Moderate)
2020-12-01
oval:org.opensuse.security:def:35047
P
Security update for jasper (Important)
2020-12-01
BACK