Comment 8 for bug 260904

Revision history for this message
Kees Cook (kees) wrote :

The crash is actually happening in the libjpeg (libjpeg6b) memory space.

Disassembly shows:
0x7f19ef4b1e3a <read_markers+3066>: mov %rax,(%rdx)

This code comes from this following area:
7f19ef4a1000-7f19ef4c3000 r-xp 00000000 08:03 167448 /usr/lib/libjpeg.so.62.0.0