PT-2014-1798 · Lead Technologies+1 · Jbig-Kit+1

Florian Weimer

·

Published

2014-04-11

·

Updated

2024-06-15

·

CVE-2013-6369

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JBIG-KIT versions prior to 2.1
Description The issue is related to a stack-based buffer overflow in the jbg dec in function in libjbig/jbig.c of JBIG-KIT. This can be exploited remotely, potentially leading to a denial of service (application crash) and possibly allowing the execution of arbitrary code via a crafted image file. The vulnerability may compromise the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 2.1, update to version 2.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the jbg dec in function in libjbig/jbig.c until a patch is available. Avoid using crafted image files that could exploit the buffer overflow in the affected function until the issue is resolved.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-04128
BDU:2015-09751
CVE-2013-6369
DSA-2900-1
MGASA-2014-0174
OPENSUSE-SU-2024:10541-1
USN-2190-1

Affected Products

Jbig-Kit
Ubuntu