Skip to content

Potential DoS vulnerabilities via crafted JPEG input #18

Description

@matteoalba

Hello!

During some fuzz-testing of jpeg2png, I identified two classes of reproducible denial-of-service vulnerabilities that can be triggered by any caller processing JPEG files from untrusted sources. Since I couldn't find a SECURITY.md or a security policy, I'm opening this issue to ask about the preferred channel for responsible disclosure before sharing the full details (POC files, ASan traces, reproducer steps).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions