oss-sec mailing list archives

Re: Stack smashing in libjpeg-turbo


From: Bastien ROUCARIES <roucaries.bastien () gmail com>
Date: Sat, 22 Nov 2014 21:15:21 +0100

On Thu, Nov 6, 2014 at 10:27 PM, Bastien ROUCARIES
<roucaries.bastien () gmail com> wrote:
Hi,

Passing special crafted jpeg file to imagemagick (convert -rotate 270
003632r270.jpg junk.jpg) could lead to stack smashing in libjpeg.so.62
(libjpeg-turbo).

This bug is triggered  by setting the optimize coding member of the
JPEG initialization structure to TRUE. If this flag set it to FALSE,
ImageMagick completes without complaint.

Wokarround could consist to turn off compression optimization in
imagemagick to prevent the stack smash.

Please assing me CVE and make a cc to  768369 () bugs debian org.

We get a reduced test case that does not need imagemagick. The bug lie
in libjpeg-turbo. Upstream is investigating


Bastien


Current thread: