An issue was found in libjpeg-turbo 2.0.1. A heap-based buffer over-read in the put_pixel_rows function in wrbmp.c, as demonstrated by djpeg. References: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/305
Created libjpeg-turbo tracking bugs for this issue: Affects: fedora-all [bug 1656219] Created mingw-libjpeg-turbo tracking bugs for this issue: Affects: epel-7 [bug 1656222] Affects: epel-all [bug 1656220]
Looks like this was introduced by https://github.com/libjpeg-turbo/libjpeg-turbo/commit/aa7459050d7a50e1d8a99488902d41fbc118a50f
Statement: This issue did not affect the versions of libjpeg-turbo as shipped with Red Hat Enterprise Linux 6 and 7.