Mandriva Linux Security Advisory : jbigkit (MDVSA-2014:077)

medium Nessus Plugin ID 73489

Synopsis

The remote Mandriva Linux host is missing one or more security updates.

Description

A vulnerability has been discovered and corrected in jbigkit :

Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted image file (CVE-2013-6369).

The updated packages for mbs1 have been upgraded to the 2.1 version and the packages for mes5 has been patched to resolve this security flaw.

Solution

Update the affected jbigkit, lib64jbig-devel and / or lib64jbig1 packages.

Plugin Details

Severity: Medium

ID: 73489

File Name: mandriva_MDVSA-2014-077.nasl

Version: 1.6

Type: local

Published: 4/14/2014

Updated: 1/6/2021

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Information

CPE: p-cpe:/a:mandriva:linux:jbigkit, p-cpe:/a:mandriva:linux:lib64jbig-devel, p-cpe:/a:mandriva:linux:lib64jbig1, cpe:/o:mandriva:business_server:1

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/Mandrake/release, Host/Mandrake/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 4/11/2014

Reference Information

CVE: CVE-2013-6369

BID: 66697

MDVSA: 2014:077