LWN.net Logo

libjpeg-turbo: code execution

Package(s):libjpeg-turbo CVE #(s):CVE-2012-2806
Created:August 1, 2012 Updated:April 8, 2013
Description: From the Novell bugzilla:

A Heap-based buffer overflow was found in the way libjpeg-turbo decompressed certain corrupt JPEG images in which the component count was erroneously set to a large value. An attacker could create a specially-crafted JPEG image that, when opened, could cause an application using libpng to crash or, possibly, execute arbitrary code with the privileges of the user running the application.

Alerts:
openSUSE openSUSE-SU-2012:0932-1 2012-08-01
Mandriva MDVSA-2012:121 2012-08-01
Mageia MGASA-2012-0203 2012-08-06
Fedora FEDORA-2012-10721 2012-08-09
Gentoo 201209-13 2012-09-26
Mandriva MDVSA-2013:044 2013-04-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds