« Volver al listado

CVE-2006-3005

Estado: ModificadaMedia (5)—

The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3005",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-06-13T10:02:00.000",
  "references": [
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=130889",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/20563",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200606-11.xml",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/26317",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/31451",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://bugs.gentoo.org/show_bug.cgi?id=130889",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/20563",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.gentoo.org/security/en/glsa/glsa-200606-11.xml",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/26317",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/31451",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The JPEG library in media-libs/jpeg before 6b-r7 on Gentoo Linux is built without the -maxmem feature, which could allow context-dependent attackers to cause a denial of service (memory exhaustion) via a crafted JPEG file that exceeds the intended memory limits."
    }
  ],
  "lastModified": "2026-06-16T22:26:12.710",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gentoo:media-libs_jpeg:6b:r2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "270095EA-4F09-40D0-AEF6-346D4B2344FF"
            },
            {
              "criteria": "cpe:2.3:a:gentoo:media-libs_jpeg:6b:r3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8E05154-651A-4803-82C1-4B47C3638C2F"
            },
            {
              "criteria": "cpe:2.3:a:gentoo:media-libs_jpeg:6b:r4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8F65B8A1-58DC-4B18-88EB-6D07324E7ECE"
            },
            {
              "criteria": "cpe:2.3:a:gentoo:media-libs_jpeg:6b:r5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "82A41614-8C8B-4F17-8A43-2FB3371E34DC"
            },
            {
              "criteria": "cpe:2.3:a:gentoo:media-libs_jpeg:6b:r6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5F87E31E-8765-44BF-8552-163356EDA1CF"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "647BA336-5538-4972-9271-383A0EC9378E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Red Hat does not consider this a security issue.  It is expected behavior that a large input file will cause the processing program to use a large amount of memory.",
      "lastModified": "2006-08-24T00:00:00",
      "organization": "Red Hat"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}