PT-2006-1058 · Independent Jpeg · Media-Libs/Jpeg
Tavis Ormandy
·
Publicado
2006-06-11
·
Atualizado
2017-07-20
·
CVE-2006-3005
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
media-libs/jpeg versions prior to 6b-r7
Description:
The issue concerns the JPEG library in media-libs/jpeg, which is built without the -maxmem feature. This could allow attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits. The exploitation of this issue can be done remotely.
Recommendations:
For versions prior to 6b-r7, update to version 6b-r7 or later to resolve the issue. As a temporary workaround, consider restricting the processing of JPEG files from untrusted sources to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Media-Libs/Jpeg