Buffer overflow in the JPEG (JPG) parsing engine in the Microsoft
Graphic Device Interface Plus (GDI+) component, GDIPlus.dll, allows
remote attackers to execute arbitrary code via a JPEG image with a
small JPEG COM field length that is normalized to a large integer
length before a memory copy operation.