libjpeg 9c has a large loop because read_pixel in rdtarga.c mishandles EOF.
The product performs an iteration or loop without sufficiently limiting the number of times that the loop is executed.
Link | Tags |
---|---|
https://github.com/ChijinZ/security_advisories/tree/master/libjpeg-v9c | third party advisory |
https://github.com/ChijinZ/security_advisories/blob/master/libjpeg-v9c/mail.pdf | third party advisory mailing list |
http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00015.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-05/msg00015.html | vendor advisory |
https://access.redhat.com/errata/RHSA-2019:2052 | vendor advisory |
https://bugs.gentoo.org/727908 | |
http://www.ijg.org/files/jpegsrc.v9d.tar.gz |