CVE-2016-3616
published 2017-02-13CVE-2016-3616: The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code…
PriorityP342high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
4.39%
90.2th percentile
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | libjpeg-turbo | < libjpeg-turbo 1:1.4.2-1 (bookworm) | libjpeg-turbo 1:1.4.2-1 (bookworm) |
| debian | libjpeg6b | < libjpeg-turbo 1:1.4.2-1 (bookworm) | libjpeg-turbo 1:1.4.2-1 (bookworm) |
| debian | libjpeg9 | < libjpeg-turbo 1:1.4.2-1 (bookworm) | libjpeg-turbo 1:1.4.2-1 (bookworm) |
| libjpeg-turbo | libjpeg-turbo | — | — |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:1.4.2-1 | 1:1.4.2-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:1.4.2-1 | 1:1.4.2-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:1.4.2-1 | 1:1.4.2-1 |
| libjpeg-turbo | libjpeg-turbo | >= 0 < 1:1.4.2-1 | 1:1.4.2-1 |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
vendor_ubuntu8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pj5x-cj5m-45mx: The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrar
ghsa_unreviewed·2022-05-14
CVE-2016-3616 [HIGH] CWE-476 GHSA-pj5x-cj5m-45mx: The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrar
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
OSV
libjpeg9 vulnerabilities
osv·2022-03-23·CVSS 8.8
CVE-2016-3616 [HIGH] libjpeg9 vulnerabilities
libjpeg9 vulnerabilities
Aladdin Mubaied discovered that the cjpeg utility in libjpeg9 did not properly
validate the input image's size. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2016-3616)
It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
certain input. An attacker could possibly use these issues to cause a denial of
service. (CVE-2018-11212, CVE-2018-11813, CVE-2020-14152, CVE-2020-14153)
It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
memory when supplied with certain input. An attacker could possibly use these
issues to cause a denial of service or execute arbitrary code.
(CVE-2018-11213, CVE-2018-11214)
OSV
CVE-2016-3616: The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrar
osv·2017-02-13·CVSS 8.8
CVE-2016-3616 [HIGH] CVE-2016-3616: The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrar
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
Ubuntu
libjpeg9 vulnerabilities
vendor_ubuntu·2022-03-23·CVSS 8.8
CVE-2020-14153 [HIGH] libjpeg9 vulnerabilities
Title: libjpeg9 vulnerabilities
Summary: Several security issues were fixed in libjpeg9.
Aladdin Mubaied discovered that the cjpeg utility in libjpeg9 did not properly
validate the input image's size. An attacker could possibly use this issue to
cause a denial of service or execute arbitrary code. (CVE-2016-3616)
It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
certain input. An attacker could possibly use these issues to cause a denial of
service. (CVE-2018-11212, CVE-2018-11813, CVE-2020-14152, CVE-2020-14153)
It was discovered that the cjpeg utility in libjpeg9 incorrectly handled
memory when supplied with certain input. An attacker could possibly use these
issues to cause a denial of service or execute arbitrary code.
(CVE-2018-11213, CVE-2018-11214)
Instru
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2018-07-10
CVE-2014-9092 libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: libjpeg-turbo could be made to crash or run programs as your login if it
opened a specially crafted file.
USN-3706-1 fixed a vulnerability in libjpeg-turbo. This update provides
the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that libjpeg-turbo incorrectly handled certain malformed
JPEG images. If a user or automated system were tricked into opening a
specially crafted JPEG image, a remote attacker could cause libjpeg-turbo
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
libjpeg-turbo vulnerabilities
vendor_ubuntu·2018-07-09
CVE-2014-9092 libjpeg-turbo vulnerabilities
Title: libjpeg-turbo vulnerabilities
Summary: libjpeg-turbo could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that libjpeg-turbo incorrectly handled certain malformed
JPEG images. If a user or automated system were tricked into opening a
specially crafted JPEG image, a remote attacker could cause libjpeg-turbo
to crash, resulting in a denial of service, or possibly execute arbitrary
code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
libjpeg: null pointer dereference in cjpeg
vendor_redhat·2016-03-30·CVSS 8.8
CVE-2016-3616 [HIGH] CWE-476 libjpeg: null pointer dereference in cjpeg
libjpeg: null pointer dereference in cjpeg
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
Package: libjpeg (Red Hat Enterprise Linux 5) - Will not fix
Package: libjpeg-turbo (Red Hat Enterprise Linux 6) - Will not fix
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Will not fix
Debian
CVE-2016-3616: libjpeg-turbo - The cjpeg utility in libjpeg allows remote attackers to cause a denial of servic...
vendor_debian·2016·CVSS 8.8
CVE-2016-3616 [HIGH] CVE-2016-3616: libjpeg-turbo - The cjpeg utility in libjpeg allows remote attackers to cause a denial of servic...
The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.
Scope: local
bookworm: resolved (fixed in 1:1.4.2-1)
bullseye: resolved (fixed in 1:1.4.2-1)
forky: resolved (fixed in 1:1.4.2-1)
sid: resolved (fixed in 1:1.4.2-1)
trixie: resolved (fixed in 1:1.4.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-3616 libjpeg-turbo: libjpeg: null pointer dereference in cjpeg [fedora-all]
bugzilla·2016-03-30·CVSS 8.8
CVE-2016-3616 [HIGH] CVE-2016-3616 libjpeg-turbo: libjpeg: null pointer dereference in cjpeg [fedora-all]
CVE-2016-3616 libjpeg-turbo: libjpeg: null pointer dereference in cjpeg [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2016-3616 mingw-libjpeg-turbo: libjpeg: null pointer dereference in cjpeg [fedora-all]
bugzilla·2016-03-30·CVSS 8.8
CVE-2016-3616 [HIGH] CVE-2016-3616 mingw-libjpeg-turbo: libjpeg: null pointer dereference in cjpeg [fedora-all]
CVE-2016-3616 mingw-libjpeg-turbo: libjpeg: null pointer dereference in cjpeg [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-3616 libjpeg: null pointer dereference in cjpeg
bugzilla·2016-03-21·CVSS 8.8
CVE-2016-3616 [HIGH] CVE-2016-3616 libjpeg: null pointer dereference in cjpeg
CVE-2016-3616 libjpeg: null pointer dereference in cjpeg
A null pointer dereference vulnerability was reported in libjpeg library in cjpeg component. A maliciously crafted file could cause an application to crash. In specific cases this may also allow the attacker to remotely execute commands.
Discussion:
Original bug report with reproducer attached:
https://bugzilla.redhat.com/show_bug.cgi?id=1318509
---
Acknowledgments:
Name: Aladdin Mubaied
---
Analysis at https://bugzilla.redhat.com/show_bug.cgi?id=1318509#c4
---
Created libjpeg-turbo tracking bugs for this issue:
Affects: fedora-all [bug 1322301]
---
Created mingw-libjpeg-turbo tracking bugs for this issue:
Affects: fedora-all [bug 1322302]
---
Also disclosed on oss-security mailing list via:
http://www.openwall.com/l
Bugzilla
null pointer dereference in libjpeg library in cjpeg
bugzilla·2016-03-17·CVSS 8.8
[HIGH] null pointer dereference in libjpeg library in cjpeg
null pointer dereference in libjpeg library in cjpeg
Created attachment 1137318
crasher
I would like to report a null pointer dereference in libjpeg library in rdppm.c:153. here is the details:
This bug can be used to cause a denial of service attack and some cases remote code execution if the library is used in a system accepts users input. please assign a cve for this issue.
$ cjpeg crasher
Starting program: /opt/libjpeg/bin/cjpeg crasher
Program received signal SIGSEGV, Segmentation fault.
bt:
*#0 get_text_gray_row (cinfo=0x7fffffffe2c0, sinfo=) at rdppm.c:153
1 0x0000000000401996 in main (argc=0x2, argv=0x7fffffffe618) at cjpeg.c:6**42
2 0x00007ffff7738af5 in __libc_start_main () from /lib64/libc.so.6
3 0x0000000000401e2d in _start ()
*ptr++ = rescale[read_pbm_integer(cinfo, infi
https://access.redhat.com/errata/RHSA-2019:2052https://bugzilla.redhat.com/show_bug.cgi?id=1318509https://bugzilla.redhat.com/show_bug.cgi?id=1319661https://lists.debian.org/debian-lts-announce/2019/01/msg00015.htmlhttps://usn.ubuntu.com/3706-1/https://usn.ubuntu.com/3706-2/https://access.redhat.com/errata/RHSA-2019:2052https://bugzilla.redhat.com/show_bug.cgi?id=1318509https://bugzilla.redhat.com/show_bug.cgi?id=1319661https://lists.debian.org/debian-lts-announce/2019/01/msg00015.htmlhttps://usn.ubuntu.com/3706-1/https://usn.ubuntu.com/3706-2/
2017-02-13
Published