Bug ID 1135719
Summary VUL-1: CVE-2019-12212: Stack exhaustion due to improper process of a special crafted JXR file
Classification openSUSE
Product openSUSE Distribution
Version Leap 42.3
Hardware Other
URL https://smash.suse.de/issue/233331/
OS Other
Status NEW
Severity Minor
Priority P5 - None
Component Security
Assignee nick.schrader@iserv-gis.de
Reporter atoptsoglou@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2019-12212

When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function
of JXRMeta.c repeatedly calls itself due to improper processing of the file,
eventually causing stack exhaustion. An attacker can achieve a remote denial of
service attack by sending a specially constructed file.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-12212
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12212
https://sourceforge.net/p/freeimage/discussion/36111/thread/e06734bed5/


You are receiving this mail because: