Vulnerability in the libjpeg-turbo library

In libjpeg-turbo, a library for encoding and decoding images in JPEG format, identified vulnerability (CVE-2019-2201), leading to an integer overflow and subsequent heap corruption when processing specially crafted JPEG files. Potentially, the vulnerability does not rule out the possibility of creating an exploit for executing code on the system (to exploit this, it requires processing a very large image with a resolution of 26755 x 26755).

The issue was quietly fixed in release 2.0.3, but apparently, it was not completely resolved and additional attack vectors remain. In the distributions, the issue remains unpatched ( Why didn't they call me back-6, or be careful, usernameDebian, Arch, SUSE/openSUSE, Alpine, Ubuntu).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster