Security Fix(es):
The PPM reader in libjpeg-turbo through 2.0.90 mishandles use of tjLoadImage for loading a 16-bit binary PPM file into a grayscale buffer and loading a 16-bit binary PGM file into an RGB buffer. This is related to a heap-based buffer overflow in the getwordrgb_row function in rdppm.c.(CVE-2021-46822)
{
"severity": "Medium"
}{
"x86_64": [
"libjpeg-turbo-debugsource-2.0.5-2.oe1.x86_64.rpm",
"libjpeg-turbo-devel-2.0.5-2.oe1.x86_64.rpm",
"libjpeg-turbo-2.0.5-2.oe1.x86_64.rpm",
"libjpeg-turbo-debuginfo-2.0.5-2.oe1.x86_64.rpm"
],
"src": [
"libjpeg-turbo-2.0.5-2.oe1.src.rpm"
],
"aarch64": [
"libjpeg-turbo-devel-2.0.5-2.oe1.aarch64.rpm",
"libjpeg-turbo-debugsource-2.0.5-2.oe1.aarch64.rpm",
"libjpeg-turbo-2.0.5-2.oe1.aarch64.rpm",
"libjpeg-turbo-debuginfo-2.0.5-2.oe1.aarch64.rpm"
],
"noarch": [
"libjpeg-turbo-help-2.0.5-2.oe1.noarch.rpm"
]
}
{
"x86_64": [
"libjpeg-turbo-devel-2.0.5-2.oe1.x86_64.rpm",
"libjpeg-turbo-debuginfo-2.0.5-2.oe1.x86_64.rpm",
"libjpeg-turbo-debugsource-2.0.5-2.oe1.x86_64.rpm",
"libjpeg-turbo-2.0.5-2.oe1.x86_64.rpm"
],
"src": [
"libjpeg-turbo-2.0.5-2.oe1.src.rpm"
],
"aarch64": [
"libjpeg-turbo-devel-2.0.5-2.oe1.aarch64.rpm",
"libjpeg-turbo-debugsource-2.0.5-2.oe1.aarch64.rpm",
"libjpeg-turbo-debuginfo-2.0.5-2.oe1.aarch64.rpm",
"libjpeg-turbo-2.0.5-2.oe1.aarch64.rpm"
],
"noarch": [
"libjpeg-turbo-help-2.0.5-2.oe1.noarch.rpm"
]
}