The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.
CVSS Details
- CVSS 3.1 Base Score: 4.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade dev-util/insight.Upgrade www-client/uzbl.Upgrade net-ftp/lftp.Upgrade dev-lang/tk.Upgrade dev-perl/perl-tk.Upgrade media-libs/jpeg.Upgrade app-misc/beanstalkd.Upgrade net-mail/mlmmj.Upgrade media-gfx/splashutils.Upgrade sys-apps/acl.Upgrade app-arch/ncompress.Upgrade sys-auth/pam_krb5.Upgrade x11-libs/gtk+.Upgrade dev-util/sourcenav.Upgrade app-text/dvipng.Upgrade x11-apps/xinit.Upgrade dev-libs/liblzw.Upgrade app-text/gv.Upgrade kde-base/kget.Upgrade x11-misc/slim.Upgrade kde-base/kdm.Upgrade app-arch/gzip.Upgrade net-misc/iputils.Upgrade sys-apps/pmount.Upgrade media-tv/dvbstreamer.Upgrade app-antivirus/bitdefender-console.Upgrade sys-devel/m4.Upgrade sys-block/partimage. | Oct 30, 2017 | Jun 13, 2006 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub