CVE-2012-2806Out-of-bounds Write in Libjpeg-turbo

Severity
8.8HIGHNVD
EPSS
2.4%
top 15.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 13
Latest updateMay 17

Description

Heap-based buffer overflow in the get_sos function in jdmarker.c in libjpeg-turbo 1.2.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large component count in the header of a JPEG image.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

1
GHSA
GHSA-hh76-h9xr-wpjv: Heap-based buffer overflow in the get_sos function in jdmarker2022-05-17

📋Vendor Advisories

1
Debian
CVE-2012-2806: libjpeg-turbo - Heap-based buffer overflow in the get_sos function in jdmarker.c in libjpeg-turb...2012

💬Community

3
Bugzilla
CVE-2012-2806 libjpeg-turbo: Heap-based buffer overflow when decompressing corrupt JPEG images [fedora-all]2012-07-17
Bugzilla
CVE-2012-2806 libjpeg-turbo: Heap-based buffer overflow when decompressing corrupt JPEG images2012-05-31
Bugzilla
Null-pointer execution/null out of bounds write at libjpeg/jdmarker.c2012-05-30