<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Recent changes to 14: null pointer dereference incjpeg</title><link>https://sourceforge.net/p/libjpeg/bugs/14/</link><description>Recent changes to 14: null pointer dereference incjpeg</description><atom:link href="https://sourceforge.net/p/libjpeg/bugs/14/feed.rss" rel="self"/><language>en</language><lastBuildDate>Wed, 16 Mar 2016 22:43:33 -0000</lastBuildDate><atom:link href="https://sourceforge.net/p/libjpeg/bugs/14/feed.rss" rel="self" type="application/rss+xml"/><item><title>#14 null pointer dereference incjpeg</title><link>https://sourceforge.net/p/libjpeg/bugs/14/?limit=25#9175</link><description>&lt;div class="markdown_content"&gt;&lt;ul&gt;
&lt;li&gt;Description has changed:&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Diff:&lt;/p&gt;
&lt;div class="codehilite"&gt;&lt;pre&gt;&lt;span class="gd"&gt;--- old&lt;/span&gt;
&lt;span class="gi"&gt;+++ new&lt;/span&gt;
&lt;span class="gu"&gt;@@ -22,3 +22,5 @@&lt;/span&gt;
 gdb$ $8 = 0x92d91bc1
 gdb$ x/x 0x92d91bc1
 0x92d91bc1:    Cannot access memory at address 0x92d91bc1
&lt;span class="gi"&gt;+&lt;/span&gt;
&lt;span class="gi"&gt;+Aladdin Mubaied&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;

&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Wed, 16 Mar 2016 22:43:33 -0000</pubDate><guid>https://sourceforge.netae17a6500ba74d515d161085b9587b1187656c60</guid></item><item><title>null pointer dereference incjpeg</title><link>https://sourceforge.net/p/libjpeg/bugs/14/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;I would like to report a null pointer derefernece in libjpeg library in rdppm.c:153. here is the details:&lt;/p&gt;
&lt;p&gt;This bug can be used to cause a denial of service attack and some cases remote code execution if the library is used in a system accepts users input.&lt;/p&gt;
&lt;p&gt;$ /opt/libjpeg/bin/cjpeg crasher&lt;/p&gt;
&lt;p&gt;Starting program: /opt/libjpeg/bin/cjpeg crasher&lt;/p&gt;
&lt;p&gt;Program received signal SIGSEGV, Segmentation fault.&lt;/p&gt;
&lt;p&gt;*#0  get_text_gray_row (cinfo=0x7fffffffe2c0, sinfo=&amp;lt;optimized out=""&amp;gt;) at rdppm.c:153&lt;/p&gt;
&lt;h1 id="1-0x0000000000401996-in-main-argc0x2-argv0x7fffffffe618-at-cjpegc642"&gt;1  0x0000000000401996 in main (argc=0x2, argv=0x7fffffffe618) at cjpeg.c:6**42&lt;/h1&gt;
&lt;h1 id="2-0x00007ffff7738af5-in-__libc_start_main-from-lib64libcso6"&gt;2  0x00007ffff7738af5 in __libc_start_main () from /lib64/libc.so.6&lt;/h1&gt;
&lt;h1 id="3-0x0000000000401e2d-in-_start"&gt;3  0x0000000000401e2d in _start ()&lt;/h1&gt;
&lt;p&gt;*ptr++ = rescale&lt;span&gt;[read_pbm_integer(cinfo, infile)]&lt;/span&gt;;&lt;/p&gt;
&lt;p&gt;=&amp;gt; 0x407b08 &amp;lt;get_text_gray_row+200&amp;gt;:    movzx  esi,BYTE PTR &lt;span&gt;[r13+rcx*1+0x0]&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;gdb$ p $r13+$rcx*1+0x0&lt;br/&gt;
gdb$ $8 = 0x92d91bc1&lt;br/&gt;
gdb$ x/x 0x92d91bc1&lt;br/&gt;
0x92d91bc1: Cannot access memory at address 0x92d91bc1&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Wed, 16 Mar 2016 22:43:05 -0000</pubDate><guid>https://sourceforge.net6b08345c796a509690e70a3b44ecad69e6bfb0a2</guid></item><item><title>null pointer dereference incjpeg</title><link>https://sourceforge.net/p/libjpeg/bugs/14/</link><description>&lt;div class="markdown_content"&gt;&lt;p&gt;Ticket 14 has been modified: null pointer dereference incjpeg&lt;br/&gt;
Edited By: Anonymous (*anonymous)&lt;br/&gt;
Description updated:&lt;br/&gt;
--- description-old&lt;/p&gt;
&lt;p&gt;+++ description-new&lt;/p&gt;
&lt;p&gt;@@ -22,4 +22,6 @@&lt;/p&gt;
&lt;p&gt;gdb$ $8 = 0x92d91bc1&lt;br/&gt;
 gdb$ x/x 0x92d91bc1&lt;br/&gt;
 0x92d91bc1:    Cannot access memory at address 0x92d91bc1&lt;br/&gt;
+&lt;br/&gt;
+Aladdin Mubaied&lt;/p&gt;&lt;/div&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Anonymous</dc:creator><pubDate>Wed, 16 Mar 2016 22:43:05 -0000</pubDate><guid>https://sourceforge.netf3aaa31d9db5e2b98ba8c3140cb9e62fb2800091</guid></item></channel></rss>