PT-2014-1798 · Lead Technologies+1 · Jbig-Kit+1

Florian Weimer

·

Publicado

2014-04-11

·

Atualizado

2024-06-15

·

CVE-2013-6369

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JBIG-KIT versions prior to 2.1
Description The issue is related to a stack-based buffer overflow in the jbg dec in function in libjbig/jbig.c of JBIG-KIT. This can be exploited remotely, potentially leading to a denial of service (application crash) and possibly allowing the execution of arbitrary code via a crafted image file. The vulnerability may compromise the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 2.1, update to version 2.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the jbg dec in function in libjbig/jbig.c until a patch is available. Avoid using crafted image files that could exploit the buffer overflow in the affected function until the issue is resolved.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04128
BDU:2015-09751
CVE-2013-6369
DSA-2900-1
MGASA-2014-0174
OPENSUSE-SU-2024:10541-1
USN-2190-1

Produtos afetados

Jbig-Kit
Ubuntu