jbig2imagecompose in jbig2_image.c in Artifex jbig2dec before 0.18 has a heap-based buffer overflow.
[
{
"source": "https://github.com/artifexsoftware/jbig2dec/commit/0726320a4b55078e9d8deb590e477d598b3da66e",
"digest": {
"length": 2314.0,
"function_hash": "155900799814058220493720912559208313050"
},
"id": "CVE-2020-12268-924c29ab",
"signature_version": "v1",
"deprecated": false,
"target": {
"function": "jbig2_image_compose",
"file": "jbig2_image.c"
},
"signature_type": "Function"
},
{
"source": "https://github.com/artifexsoftware/jbig2dec/commit/0726320a4b55078e9d8deb590e477d598b3da66e",
"digest": {
"line_hashes": [
"61396668555749811848068125231363856132",
"252418362158374979476010566018152555753",
"246957501170545357834171659149094779928",
"165385627614570169697733398513774003925",
"234582650076415910176916236025065889186",
"220260793454758799366951002293607683045",
"110233043273871289438074883028102066942"
],
"threshold": 0.9
},
"id": "CVE-2020-12268-c0987598",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "jbig2_image.c"
},
"signature_type": "Line"
}
]