Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Informations
Name CVE-2012-2806 First vendor Publication 2012-08-13
Vendor Cve Last vendor Modification 2023-12-20

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

Heap-based buffer overflow in the get_sos function in jdmarker.c in libjpeg-turbo 1.2.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large component count in the header of a JPEG image.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2806

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-787 Out-of-bounds Write (CWE/SANS Top 25)

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

OpenVAS Exploits

Date Description
2012-09-26 Name : Gentoo Security Advisory GLSA 201209-13 (libjpeg-turbo)
File : nvt/glsa_201209_13.nasl
2012-08-14 Name : Fedora Update for libjpeg-turbo FEDORA-2012-10721
File : nvt/gb_fedora_2012_10721_libjpeg-turbo_fc16.nasl
2012-08-10 Name : FreeBSD Ports: libjpeg-turbo
File : nvt/freebsd_libjpeg-turbo.nasl
2012-08-03 Name : Mandriva Update for libjpeg-turbo MDVSA-2012:121 (libjpeg-turbo)
File : nvt/gb_mandriva_MDVSA_2012_121.nasl

Nessus® Vulnerability Scanner

Date Description
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2012-469.nasl - Type : ACT_GATHER_INFO
2013-04-20 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2013-044.nasl - Type : ACT_GATHER_INFO
2013-01-25 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_jpeg-120724.nasl - Type : ACT_GATHER_INFO
2012-09-27 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201209-13.nasl - Type : ACT_GATHER_INFO
2012-09-06 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2012-121.nasl - Type : ACT_GATHER_INFO
2012-08-17 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_jpeg-8233.nasl - Type : ACT_GATHER_INFO
2012-08-10 Name : The remote Fedora host is missing a security update.
File : fedora_2012-10721.nasl - Type : ACT_GATHER_INFO
2012-07-19 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_a460035ed11111e1aff7001fd056c417.nasl - Type : ACT_GATHER_INFO

Sources (Detail)

http://libjpeg-turbo.svn.sourceforge.net/viewvc/libjpeg-turbo?view=revision&a...
http://osvdb.org/84040
http://secunia.com/advisories/49883
http://secunia.com/advisories/50753
http://security.gentoo.org/glsa/glsa-201209-13.xml
http://www.mandriva.com/security/advisories?name=MDVSA-2012:121
http://www.openwall.com/lists/oss-security/2012/07/17/3
http://www.securityfocus.com/bid/54480
https://bugzilla.mozilla.org/show_bug.cgi?id=759802
https://bugzilla.redhat.com/show_bug.cgi?id=826849
https://exchange.xforce.ibmcloud.com/vulnerabilities/76952
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
Date Informations
2023-12-21 21:28:39
  • Multiple Updates
2023-11-07 21:46:51
  • Multiple Updates
2021-05-04 12:20:04
  • Multiple Updates
2021-04-22 01:23:47
  • Multiple Updates
2020-05-23 00:33:45
  • Multiple Updates
2017-08-29 09:23:50
  • Multiple Updates
2016-06-28 19:09:56
  • Multiple Updates
2016-04-26 21:52:51
  • Multiple Updates
2014-06-14 13:32:58
  • Multiple Updates
2014-02-17 11:10:51
  • Multiple Updates
2013-05-10 22:40:36
  • Multiple Updates
2013-04-05 13:18:46
  • Multiple Updates
2013-03-02 13:19:00
  • Multiple Updates
2013-02-07 13:20:16
  • Multiple Updates