Fresco uses libjpeg-turbo 1.5.3 to have CVE-2020-17541 and CVE-2018-14498 vulnerabilities. Is there a repair plan?
Open
- Dominant language
- Kotlin
- Stars
- 17.2k
- Forks
- 3.7k
- PR merge metrics
- No merged PRs in 30d
Description
### Description
libjpeg-turbo 1.5.3 has CVE-2020-17541 and CVE-2018-14498 vulnerabilities. I tested the version of libjpeg-turbo 2.1.0 and the vulnerability has been resolved. Can fresco be able to upgrade the version of libjpeg?
### Solution
https://github.com/libjpeg-turbo/libjpeg-turbo
Contributor guide
Assessment
This issue has not been assessed yet.