The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://usn.ubuntu.com/3706-2/ | third party advisory vendor advisory |
https://usn.ubuntu.com/3706-1/ | third party advisory vendor advisory |
https://lists.debian.org/debian-lts-announce/2019/01/msg00015.html | third party advisory mailing list |
https://bugzilla.redhat.com/show_bug.cgi?id=1318509 | third party advisory vdb entry issue tracking |
https://bugzilla.redhat.com/show_bug.cgi?id=1319661 | third party advisory vdb entry issue tracking |
https://access.redhat.com/errata/RHSA-2019:2052 | vendor advisory |