CVE-2006-3005: Medium severity Gentoo Media-libs Jpeg vulnerability
Published Jun 13, 2006
·Updated
The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.
Affected Software
6 affected components
Gentoo Media-libs Jpeg=6b-r2
Gentoo Media-libs Jpeg=6b-r3
Gentoo Media-libs Jpeg=6b-r4
Gentoo Media-libs Jpeg=6b-r5
Gentoo Media-libs Jpeg=6b-r6
Gentoo Linux
Remediation
Patch Available
Patch Available
Event History
Jun 13, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3005?
CVE-2006-3005 has a severity rating that indicates it can lead to denial of service through memory exhaustion.
2
How do I fix CVE-2006-3005?
To fix CVE-2006-3005, update the media-libs/jpeg package to a version that includes the -maxmem feature.
3
What versions of media-libs/jpeg are affected by CVE-2006-3005?
CVE-2006-3005 affects media-libs/jpeg versions 6b-r2 through 6b-r6 on Gentoo Linux.
4
Can CVE-2006-3005 be exploited remotely?
Yes, CVE-2006-3005 can be exploited by remote attackers via crafted JPEG files.
5
What is the impact of exploiting CVE-2006-3005?
Exploitation of CVE-2006-3005 can lead to memory exhaustion, resulting in service disruptions.