REDHAT-BUG-1169845: Low severity Libjpeg-turbo Libjpeg-turbo vulnerability
A flaw in libjpeg-turbo was reported [1],[2],[3] that could lead to a local denial of service when processing a specially-crafted JPEG issue.
One of the reports indicate that this only affects versions of libjpeg-turbo prior to 1.3.1 due to 1.3.1 rejecting the malformed image due to duplicate SOI markers.
Upstream has fixes for this issue [4],[5]. Also refer to the upstream bug [6].
[1] http://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=26482&sid=81658bc2f51a8d9893279cd01e83783f [2] http://seclists.org/oss-sec/2014/q4/557 [3] https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=768369 [4] http://sourceforge.net/p/libjpeg-turbo/code/1365/ [5] http://sourceforge.net/p/libjpeg-turbo/code/1367/ [6] http://sourceforge.net/p/libjpeg-turbo/bugs/64/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1169845?
The severity of REDHAT-BUG-1169845 is classified as a local denial of service vulnerability.
How do I fix REDHAT-BUG-1169845?
To fix REDHAT-BUG-1169845, upgrade libjpeg-turbo to version 1.3.1 or later.
Which versions of libjpeg-turbo are affected by REDHAT-BUG-1169845?
Versions of libjpeg-turbo prior to 1.3.1 are affected by REDHAT-BUG-1169845.
What kind of issue does REDHAT-BUG-1169845 cause?
REDHAT-BUG-1169845 can cause a local denial of service when processing specially-crafted JPEG images.
Is there a workaround for REDHAT-BUG-1169845?
The recommended solution for REDHAT-BUG-1169845 is to update to the latest version of libjpeg-turbo, as there are no effective workarounds for this vulnerability.