libjpeg-turbo: User-assisted execution of arbitrary code Several integer overflows in libjpeg-turbo might allow an attacker to execute arbitrary code. libjpeg-turbo 2020-03-15 2020-03-15 699830 local, remote 2.0.3 2.0.3

libjpeg-turbo is a MMX, SSE, and SSE2 SIMD accelerated JPEG library.

It was discovered that libjpeg-turbo incorrectly handled certain JPEG images.

A remote attacker could entice a user to open a specially crafted JPEG file in an application linked against libjpeg-turbo, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition.

There is no known workaround at this time.

All libjpeg-turbo users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=media-libs/libjpeg-turbo-2.0.3"
CVE-2019-2201 whissi whissi