PT-2006-1058 · Independent Jpeg · Media-Libs/Jpeg

Tavis Ormandy

·

Published

2006-06-11

·

Updated

2017-07-20

·

CVE-2006-3005

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions: media-libs/jpeg versions prior to 6b-r7
Description: The issue concerns the JPEG library in media-libs/jpeg, which is built without the -maxmem feature. This could allow attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits. The exploitation of this issue can be done remotely.
Recommendations: For versions prior to 6b-r7, update to version 6b-r7 or later to resolve the issue. As a temporary workaround, consider restricting the processing of JPEG files from untrusted sources to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-09517
CVE-2006-3005

Affected Products

Media-Libs/Jpeg