CVE-2012-2806: D.r.commander Libjpeg-Turbo

High severity, CVSS 8.8. EPSS: 4.8% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the get_sos function in jdmarker.c in libjpeg-turbo 1.2.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large component count in the header of a JPEG image.

Affected products

Published 2012-08-13. Last modified 2026-06-16.