http://bugzilla.opensuse.org/show_bug.cgi?id=1135719 Bug ID: 1135719 Summary: VUL-1: CVE-2019-12212: Stack exhaustion due to improper process of a special crafted JXR file Classification: openSUSE Product: openSUSE Distribution Version: Leap 42.3 Hardware: Other URL: https://smash.suse.de/issue/233331/ OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Security Assignee: nick.schrader@iserv-gis.de Reporter: atoptsoglou@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2019-12212 When FreeImage 3.18.0 reads a special JXR file, the StreamCalcIFDSize function of JXRMeta.c repeatedly calls itself due to improper processing of the file, eventually causing stack exhaustion. An attacker can achieve a remote denial of service attack by sending a specially constructed file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2019-12212 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12212 https://sourceforge.net/p/freeimage/discussion/36111/thread/e06734bed5/ -- You are receiving this mail because: You are on the CC list for the bug.