CVE-2006-1060
xzgv - programming error
EPSS 4.1%
Description
Heap-based buffer overflow in zgv before 5.8 and xzgv before 0.8 might allow user-assisted attackers to execute arbitrary code via a JPEG image with more than 3 output components, such as a CMYK or YCCK color space, which causes less memory to be allocated than required.
How to fix CVE-2006-1060
To remediate CVE-2006-1060, upgrade the affected package to a fixed version below.
- Debian/xzgv—upgrade to 0.8-5.1 or later
- Debian/xzgv—upgrade to 0.7-6woody3 or later
- Debian/zgv—upgrade to 5.5-3woody3 or later
Is CVE-2006-1060 being exploited?
Low — EPSS is 4.1%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 0.8-5.1
- from 0, < 0.7-6woody3
- from 0, < 5.5-3woody3