A null pointer dereference vulnerability was reported in libjpeg library in cjpeg component. A maliciously crafted file could cause an application to crash. In specific cases this may also allow the attacker to remotely execute commands.
Original bug report with reproducer attached: https://bugzilla.redhat.com/show_bug.cgi?id=1318509
Acknowledgments: Name: Aladdin Mubaied
Analysis at https://bugzilla.redhat.com/show_bug.cgi?id=1318509#c4
Created libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 1322301]
Created mingw-libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 1322302]
Also disclosed on oss-security mailing list via: http://www.openwall.com/lists/oss-security/2016/03/30/2
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2019:2052 https://access.redhat.com/errata/RHSA-2019:2052