Red Hat Bugzilla – Bug 1319661
CVE-2016-3616 libjpeg: null pointer dereference in cjpeg
Last modified: 2018-07-18 10:51:04 EDT
A null pointer dereference vulnerability was reported in libjpeg library in cjpeg component. A maliciously crafted file could cause an application to crash. In specific cases this may also allow the attacker to remotely execute commands.
Original bug report with reproducer attached: https://bugzilla.redhat.com/show_bug.cgi?id=1318509
Acknowledgments: Name: Aladdin Mubaied
Analysis at https://bugzilla.redhat.com/show_bug.cgi?id=1318509#c4
Created libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 1322301]
Created mingw-libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 1322302]
Also disclosed on oss-security mailing list via: http://www.openwall.com/lists/oss-security/2016/03/30/2