Rashin lahani a cikin ɗakin karatu na libjpeg-turbo

В libjpeg-turbo, ɗakin karatu don ɓoyewa da yanke hotunan JPEG, gano rauni (CVE-2019-2201), yana haifar da cikar lambatu da cin hanci da rashawa na abubuwan da ke gaba yayin sarrafa fayilolin JPEG ta wata hanya. Mai yuwuwa, raunin da ya faru ba ya ware yuwuwar ƙirƙirar amfani don tsara aiwatar da lambar akan tsarin (harrin yana buƙatar sarrafa babban hoto tare da ƙuduri na 26755 x 26755).

Matsala ba tare da tallatawa ba dole ba gyarawa a cikin saki 2.0.3, amma a fili an kawar da shi ba gaba daya ba sannan kuma akwai sauran hanyoyin kai hari. A cikin rarraba matsalar ta kasance ba a gyara ba (Debian, SUSE/budeSUSE, RHEL, Fedora, Ubuntu).

source: budenet.ru

Add a comment