libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://usn.ubuntu.com/3706-1/ | vendor advisory |
https://github.com/mozilla/mozjpeg/issues/268 | third party advisory exploit |
https://github.com/libjpeg-turbo/libjpeg-turbo/pull/182 | third party advisory patch |