CVE-2020-14152 is a memory consumption vulnerability affecting IJG JPEG (libjpeg) versions prior to 9d, specifically within the djpeg component. The flaw lies in the jpeg_mem_available() function, which fails to respect the max_memory_to_use setting, potentially leading to excessive memory usage. This vulnerability carries a CVSS v3.1 score of 7.1 (High), indicating a local attack vector with low complexity, requiring user interaction, and potentially resulting in high impact to confidentiality and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9dCPE matchmatch criteria | cpe:2.3:a:ijg:libjpeg:*:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP Universal Print Driver Series (PCL 6 and PostScript) - Potential Security Vulnerabilities
Jan 29, 2025libjpeg: improper handling of max_memory_to_use setting can lead to excessive memory consumption
Jun 11, 2020In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.
Jun 9, 2020