libjpeg-turbo: code execution
Package(s): | libjpeg-turbo |
CVE #(s): | CVE-2012-2806
|
Created: | August 1, 2012 |
Updated: | April 8, 2013 |
Description: |
From the Novell bugzilla:
A Heap-based buffer overflow was found in the way libjpeg-turbo
decompressed certain corrupt JPEG images in which the component count
was erroneously set to a large value. An attacker could create a
specially-crafted JPEG image that, when opened, could cause an
application using libpng to crash or, possibly, execute arbitrary code
with the privileges of the user running the application. |
Alerts: |
|