6.8
CVSSv2

CVE-2017-9614

Published: 27/07/2017 Updated: 17/05/2024
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The fill_input_buffer function in jdatasrc.c in libjpeg-turbo 1.5.1 allows remote malicious users to cause a denial of service (invalid memory access and application crash) or possibly have unspecified other impact via a crafted jpg file. NOTE: Maintainer asserts the issue is due to a bug in downstream code caused by misuse of the libjpeg API

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

d.r.commander libjpeg-turbo 1.5.1

Vendor Advisories

An out-of-bounds read vulnerability leading to denial of service has been found in libjpeg-turbo <= 151, in the fill_input_buffer function in jdatasrcc, via a crafted JPEG file ...

Exploits

libjpeg-turbo denial of service vulnerability ====================== Author : qflbwu CVE : CVE-2017-9614 ====================== Introduction: ============= libjpeg-turbo is a JPEG image codec that uses SIMD instructions (MMX, SSE2, AVX2, NEON, AltiVec) to accelerate baseline JPEG compression and decompression on x86, x86-64, ARM, and PowerPC ...