Skip to content

Pixel flood vulnerability #69

@r3ggi

Description

@r3ggi

Hey!

I noticed that the latest jpegoptim is vulnerable to pixel flood attack. Due to unlimited memory consumption, uploading a malicious jpg file to a web application that uses jpegoptim, may cause a denial of service.

You can read more on that vulnerability here.

Proof of concept

toomanypixels

memory_consumed

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions