CVE-2020-13790

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
03/06/2020
Last modified:
07/11/2023

Description

libjpeg-turbo 2.0.4, and mozjpeg 4.0.0, has a heap-based buffer over-read in get_rgb_row() in rdppm.c via a malformed PPM input file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libjpeg-turbo:libjpeg-turbo:2.0.4:*:*:*:*:*:*:*
cpe:2.3:a:mozilla:mozjpeg:4.0.0:*:*:*:*:*:*:*