CVE-2017-15232: Null Pointer Dereference
Published Oct 11, 2017
·Updated
Last updated 25 August 2025
Other sources
libjpeg-turbo 1.5.2 has a NULL Pointer Dereference in jdpostct.c and jquant1.c via a crafted JPEG file.
— Launchpad
Affected Software
4 affected componentsFixes available
Libjpeg-turbo Libjpeg-turbo=1.5.2
debian/libjpeg-turbo
1:2.0.6-41:2.1.5-21:2.1.5-41:3.1.3-4
debian/libjpeg6b
1:6b2-4
debian/libjpeg9
1:9f-2
Remediation
Patch Available
Event History
Oct 11, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Data Sourced
via NVD·03:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:31 PM
Description
Feb 18, 2026
Data Sourced
via Ubuntu·08:58 PM
RemedyDescriptionSeverityAffected Software
May 13, 2026
Data Sourced
via Debian·03:21 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2017-15232?
CVE-2017-15232 is a vulnerability in libjpeg-turbo 1.5.2 that allows for a NULL pointer dereference via a crafted JPEG file.
2
What is the severity of CVE-2017-15232?
CVE-2017-15232 has a severity of 6.5 (medium).
3
How does CVE-2017-15232 affect libjpeg-turbo?
CVE-2017-15232 affects libjpeg-turbo version 1.5.2.
4
How do I fix CVE-2017-15232 in libjpeg-turbo?
To fix CVE-2017-15232 in libjpeg-turbo, update to version 1.5.2-2+deb10u1 (for Debian) or apply the appropriate remedy based on your operating system and package version.
5
Where can I find more information about CVE-2017-15232?
You can find more information about CVE-2017-15232 in the references section.