Skip to content

[Security] libjpeg-turbo used in this project is vulnerable  #94

@Crispy-fried-chicken

Description

@Crispy-fried-chicken

CVE-2021-46822 is a security vulnerability in libjpeg-turbo, which is used in this project. The root cause of this CVE is heap-based buffer overflow in the get_word_rgb_row function in rdppm.c.
Would you can help to check if this bug is true? If it's true, you can easily fix this vulnerability by applying this patch. Of course, I'd like to open a PR for that if necessary. Thank you for your effort and patience!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions