libjpeg-turbo CVE-2014-9092 Stack Based Buffer Overflow Vulnerability
BID:71326
CVE-2014-9092 |Info
libjpeg-turbo CVE-2014-9092 Stack Based Buffer Overflow Vulnerability
| Bugtraq ID: | 71326 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2014-9092 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 06 2014 12:00AM |
| Updated: | Apr 13 2015 09:22PM |
| Credit: | Bastien ROUCARIES |
| Vulnerable: |
Mandriva Business Server 1 X86 64 Mandriva Business Server 1 libjpeg-turbo libjpeg-turbo 1.3.1 |
| Not Vulnerable: | |
Discussion
libjpeg-turbo CVE-2014-9092 Stack Based Buffer Overflow Vulnerability
libjpeg-turbo is prone to a stack-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application or to crash the application.
libjpeg-turbo is prone to a stack-based buffer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application or to crash the application.
Exploit / POC
libjpeg-turbo CVE-2014-9092 Stack Based Buffer Overflow Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
References
libjpeg-turbo CVE-2014-9092 Stack Based Buffer Overflow Vulnerability
References:
References:
- libjpeg-turbo Homepage (libjpeg-turbo)
- Stack smashing in convert, compare (ImageMagick)
- libjpeg-turbo: CVE-2014-9092: [DOS] Stack smashing (Debian)