PT-2006-1058 · Independent Jpeg · Media-Libs/Jpeg

Tavis Ormandy

·

Publicado

2006-06-11

·

Atualizado

2017-07-20

·

CVE-2006-3005

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: media-libs/jpeg versions prior to 6b-r7
Description: The issue concerns the JPEG library in media-libs/jpeg, which is built without the -maxmem feature. This could allow attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits. The exploitation of this issue can be done remotely.
Recommendations: For versions prior to 6b-r7, update to version 6b-r7 or later to resolve the issue. As a temporary workaround, consider restricting the processing of JPEG files from untrusted sources to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

BDU:2015-09517
CVE-2006-3005

Produtos afetados

Media-Libs/Jpeg