CVE-2013-6369

medium
Published 2014-04-11 · Modified 2026-05-06
CVSS v3
CVSS v2
6.8
VIR risk
6.8

Description

Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted image file.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2013-6369

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/57731

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.0-2.1
debian debianbullseyefixed2.0-2.1
debian debianforkyfixed2.0-2.1
debian debiansidfixed2.0-2.1
debian debiantrixiefixed2.0-2.1

Application impact

VendorProductVersionsFixed
cambridge_enterprisejbig-kit{"endIncluding":"2.0"}
cambridge_enterprisejbig-kit0.5
cambridge_enterprisejbig-kit0.6
cambridge_enterprisejbig-kit0.7
cambridge_enterprisejbig-kit0.8
cambridge_enterprisejbig-kit0.9
cambridge_enterprisejbig-kit1.0
cambridge_enterprisejbig-kit1.1
cambridge_enterprisejbig-kit1.2
cambridge_enterprisejbig-kit1.3
cambridge_enterprisejbig-kit1.4
cambridge_enterprisejbig-kit1.5
cambridge_enterprisejbig-kit1.6

References

CWEs

CWE-119

Verify integrity in audit chain (admin only). AS-IS.