CVE-2014-9092: Buffer Overflow
A flaw in libjpeg-turbo was reported [1],[2],[3] that could lead to a local denial of service when processing a specially-crafted JPEG issue.
One of the reports indicate that this only affects versions of libjpeg-turbo prior to 1.3.1 due to 1.3.1 rejecting the malformed image due to duplicate SOI markers.
Upstream has fixes for this issue [4],[5]. Also refer to the upstream bug [6].
[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26482&sid=81658bc2f51a8d9893279cd01e83783f [2] http://seclists.org/oss-sec/2014/q4/557 [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=768369 [4] http://sourceforge.net/p/libjpeg-turbo/code/1365/ [5] http://sourceforge.net/p/libjpeg-turbo/code/1367/ [6] http://sourceforge.net/p/libjpeg-turbo/bugs/64/
Other sources
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2014-9092?
CVE-2014-9092 is a vulnerability that allows remote attackers to cause a denial of service (crash) by exploiting a flaw in libjpeg-turbo, a JPEG processing library.
How severe is CVE-2014-9092?
CVE-2014-9092 has a severity rating of 6.5 (medium).
Which software is affected by CVE-2014-9092?
CVE-2014-9092 affects libjpeg-turbo versions 1.3.0-0ubuntu2.1, 1:1.3.1-11, 1:1.5.2-2+deb10u1, 1:2.0.6-4, and 1:2.1.5-2.
How can I fix CVE-2014-9092?
To fix CVE-2014-9092, update your libjpeg-turbo package to version 1.3.1 or later.
Where can I find more information about CVE-2014-9092?
You can find more information about CVE-2014-9092 at the following references: [1](http://www.openwall.com/lists/oss-security/2014/11/26/8), [2](http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26482&sid=81658bc2f51a8d9893279cd01e83783f), [3](https://tapani.tarvainen.info/linux/convertbug/).