Buffer overflow in libjpeg-turbo - CVE-2014-9092

 

Buffer overflow in libjpeg-turbo - CVE-2014-9092

Published: June 14, 2021


Vulnerability identifier: #VU54092
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-9092
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error when processing Exif markers inside JPEG files. A remote attacker can create a specially crafted JPEG file, trick the victim into opening it, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

libjpeg-turbo
Fedora
mingw-libjpeg-turbo
libjpeg-turbo

How to mitigate CVE-2014-9092

Install updates from vendor's website.

libjpeg-turbo - update to 1.3.1
mingw-libjpeg-turbo - addressed in versions 1.3.1-4.el7, 1.3.1-4.fc21
libjpeg-turbo - update to 1.3.1-5.fc21

External References

Related Security Bulletins