In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://bugs.gentoo.org/727908 | issue tracking third party advisory |
http://www.ijg.org/files/jpegsrc.v9d.tar.gz | product |
https://lists.debian.org/debian-lts-announce/2020/07/msg00033.html | third party advisory mailing list |