PT-2006-1058 · Independent Jpeg · Media-Libs/Jpeg
Tavis Ormandy
·
Published
2006-06-11
·
Updated
2017-07-20
·
CVE-2006-3005
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
media-libs/jpeg versions prior to 6b-r7
Description:
The issue concerns the JPEG library in media-libs/jpeg, which is built without the -maxmem feature. This could allow attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits. The exploitation of this issue can be done remotely.
Recommendations:
For versions prior to 6b-r7, update to version 6b-r7 or later to resolve the issue. As a temporary workaround, consider restricting the processing of JPEG files from untrusted sources to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Media-Libs/Jpeg