facebook / facebook/fresco

CVE-2023-2804。libjpeg-turbo

Open
#2,808 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Kotlin
Stars
17.2k
Forks
3.7k
PR merge metrics
No merged PRs in 30d

Description

There is a security vulnerability in libjpeg-turbo, which originates from the heap buffer overflow at /libjpeg-turbo/jdmrext.c:126 in h2v2_merged_upsample_internal().

Contributor guide

Open the contributing guide

Research direction

Start by reviewing libjpeg-turbo/jdmrext.c:126 and the h2v2_merged_upsample_internal() entry point, then trace how Fresco incorporates this dependency. The issue provides no affected version, reproduction, expected change, or test target, so completion criteria must be established before implementation.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, kotlin
Domain
mobile-dev, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.