Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Jpegoptim: Initial Project Proposal (#12919)
I am requesting permission to integrate [jpegoptim](https://github.com/tjko/jpegoptim) into OSS-Fuzz. I believe that this project is a good candidate for OSS-Fuzz integration as it serves as a preeminent JPEG compression library used by many prominent projects such as [NextCloud Server](https://github.com/nextcloud/server/blob/c28fceb5d511e22030697e549c618699bce7c205/build/image-optimization.sh#L13C1-L17C3), [ImageOptim](https://github.com/ImageOptim/ImageOptim), and [Nikola](https://github.com/getnikola/nikola). For the sake of highlighting the library's importance and the risks posed by potential vulnerabilities within it, it is beneficial to consider NextCloud's usage of the library to handle image size optimization for storing user's data. Some potential risks include image corruption and loss of customer data and, as a worst -case-scenario, the exploitation of the JPEG parsing to achieve RCE on a public-network-facing file store. Please see upstream approval for integration [here](tjko/jpegoptim#182) Co-authored-by: Vitor Guidi <vitorguidi@gmail.com>
- Loading branch information