Libjpeg-turbo all version have a stack-based buffer overflow in the “transform” component. A remote attacker can send a malformed jpeg file to the service and cause arbitrary code execution or denial of service of the target service.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-17541
Reference (s):
- https://github.com/libjpeg-turbo/libjpeg-turbo/issues/392

