#VU38641 Buffer overflow in libjpeg-turbo - CVE-2017-9614
Published: July 27, 2017 / Updated: August 9, 2020
libjpeg-turbo
The libjpeg-turbo Project
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file.