8.1
CVSSv3

CVE-2020-13790

Published: 03/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

It exists that libjpeg-turbo incorrectly handled certain PPM files. An attacker could possibly use this issue to access sensitive information.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

libjpeg-turbo libjpeg-turbo 2.0.4

mozilla mozjpeg 4.0.0

Vendor Advisories

Debian Bug report logs - #962829 libjpeg-turbo: CVE-2020-13790 Package: src:libjpeg-turbo; Maintainer for src:libjpeg-turbo is Ondřej Surý <ondrej@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 14 Jun 2020 19:45:01 UTC Severity: important Tags: security, upstream Found in version lib ...
libjpeg-turbo could be made to expose sensitive information if it received a specially crafted PPM file ...