CVE-2006-3005

Description

From CVE.org

The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.

Statement

Red Hat does not consider this a security issue. It is expected behavior that a large input file will cause the processing program to use a large amount of memory.

Frequently Asked Questions

Want to get errata notifications? Sign up here.