LWN.net Logo

libjpeg: Denial of Service

Package(s):jpeg libjpeg CVE #(s):
Created:June 12, 2006 Updated:June 14, 2006
Description: Tavis Ormandy of the Gentoo Linux Auditing Team discovered that the vulnerable JPEG library ebuilds compile JPEG without the --maxmem feature which is not recommended. By enticing a user to load a specially crafted JPEG image file an attacker could cause a denial of service, due to memory exhaustion.
Alerts:
Gentoo 200606-11 2006-06-11

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds