CVE-2023-2804。libjpeg-turbo
Open
- Dominant language
- Kotlin
- Stars
- 17.2k
- Forks
- 3.7k
- PR merge metrics
- No merged PRs in 30d
Description
There is a security vulnerability in libjpeg-turbo, which originates from the heap buffer overflow at /libjpeg-turbo/jdmrext.c:126 in h2v2_merged_upsample_internal().
Contributor guide
Research direction
Start by reviewing libjpeg-turbo/jdmrext.c:126 and the h2v2_merged_upsample_internal() entry point, then trace how Fresco incorporates this dependency. The issue provides no affected version, reproduction, expected change, or test target, so completion criteria must be established before implementation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- android, kotlin
- Domain
- mobile-dev, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100