#VU23852 Out-of-bounds write in libjpeg-turbo
Published: December 31, 2019
libjpeg-turbo
The libjpeg-turbo Project
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error within tjDecompressToYUV2() and tjDecompressToYUVPlanes() functions when attempting to decompress grayscale JPEG images that were compressed with a sampling factor other than 1. A remote attacker can create a specially crafted JPEG file, pass it to the affected application, trigger out-of-bounds write and execute arbitrary code on the target system.