An issue was discovered in jpeg-compressor 0.1. The bmp_load function in stb_image.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact.
https://github.com/kornelski/jpeg-compressor/issues/13
https://github.com/fouzhe/security/tree/master/jpeg-compressor