MEDIUM
jbigkit: stack-based buffer overflow flaw
Published Apr 11, 2014
6.8
MEDIUMCVSS 2.0
EPSS 3.45%
Description
Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted image file.
Affected products
No data.
OR
- ≤ 2.0
- 0.5
- 0.6
- 0.7
- 0.8
- 0.9
- 1.0
- 1.1
- 1.2
- 1.3
- 1.4
- 1.5
- 1.6
No data.
Red Hat Enterprise Linux 7
jbigkit
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | jbigkit | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of jbigkit as shipped with Red Hat Enterprise Linux 7, as the issue was corrected before the release of Red Hat Enterprise Linux 7.
Weaknesses (2)
References (7)
- http://secunia.com/advisories/57731 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://www.securityfocus.com/bid/66697 vdb-entryx_refsource_BID
- https://access.redhat.com/security/cve/CVE-2013-6369 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1032273 x_refsource_CONFIRMIssue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2013-6369
- https://www.cl.cam.ac.uk/~mgk25/jbigkit/CHANGES x_refsource_CONFIRM
- https://www.cve.org/CVERecord?id=CVE-2013-6369
| Link | Providers | Tags |
|---|---|---|
| http://secunia.com/advisories/57731 | third-party-advisoryx_refsource_SECUNIAVendor Advisory | |
| http://www.securityfocus.com/bid/66697 | vdb-entryx_refsource_BID | |
| https://access.redhat.com/security/cve/CVE-2013-6369 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1032273 | x_refsource_CONFIRMIssue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2013-6369 | ||
| https://www.cl.cam.ac.uk/~mgk25/jbigkit/CHANGES | x_refsource_CONFIRM | |
| https://www.cve.org/CVERecord?id=CVE-2013-6369 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 11, 2014
Updated Aug 6, 2024
Reserved Nov 4, 2013
Link CVE-2013-6369
CISA Vulnrichment
Updated n/a