CVE-2006-3005

Gentoo media-libs/jpeg - Denial of Service via Memory Exhaustion

Title source: llm
STIX 2.1

Description

The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.

References (5)

Core 5
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_gentoo
http://www.gentoo.org/security/en/glsa/glsa-200606-11.xml
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20563
Issue Tracking x_refsource_confirm
http://bugs.gentoo.org/show_bug.cgi?id=130889
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/26317
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/31451

Scores

EPSS 0.0054
EPSS Percentile 67.8%

Details

Status published
Products (2)
gentoo/linux
gentoo/media-libs_jpeg 6b r2 (5 CPE variants)
Published Jun 13, 2006
Tracked Since Feb 18, 2026