CVE Vulnerabilities

CVE-2016-3616

NULL Pointer Dereference

Published: Feb 13, 2017 | Modified: Apr 20, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
6.8 MODERATE
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The cjpeg utility in libjpeg allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) or execute arbitrary code via a crafted file.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Libjpeg-turboLibjpeg-turbo7.4 (including)7.4 (including)
Red Hat Enterprise Linux 7RedHatlibjpeg-turbo-0:1.2.90-8.el7*
Libjpeg-turboUbuntuesm-infra-legacy/trusty*
Libjpeg-turboUbuntuprecise*
Libjpeg-turboUbuntutrusty*
Libjpeg-turboUbuntutrusty/esm*
Libjpeg-turboUbuntuupstream*
Libjpeg-turboUbuntuvivid/stable-phone-overlay*
Libjpeg-turboUbuntuwily*
Libjpeg9Ubuntuartful*
Libjpeg9Ubuntubionic*
Libjpeg9Ubuntuesm-apps/bionic*
Libjpeg9Ubuntuesm-apps/xenial*
Libjpeg9Ubuntuxenial*
Libjpeg9Ubuntuyakkety*
Libjpeg9Ubuntuzesty*

Potential Mitigations

References