Unknown · Libjpeg-Turbo · CVE-2021-29390
**Name of the Vulnerable Software and Affected Versions**
libjpeg-turbo version 2.0.90
**Description**
The issue is a heap-based buffer over-read in the `decompress smooth data` function in `jdcoefct.c`. This is a critical issue.
**Recommendations**
For libjpeg-turbo version 2.0.90, consider updating to a newer version that addresses this issue, as the current version has a heap-based buffer over-read vulnerability in the `decompress smooth data` function.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.