ExifImageFile::readDQT in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted JPEG file.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/skysider/openexif_vulnerabilities | third party advisory |
http://seclists.org/fulldisclosure/2017/Sep/34 | third party advisory mailing list |