VDB
GCVE-VVD-MAGEIA-2017-206
GCVE-VVD-MAGEIA-2017-206
Advisory Published
Multiple security issues have been found in the JBIG2 decoder library,
which may lead to lead to denial of service or the execution of arbitrary
code if a malformed image file (usually embedded in a PDF document) is
opened (CVE-2016-9601).
Artifex jbig2dec has a heap-based buffer over-read leading to denial of
service (application crash) because of an integer overflow in the
jbig2_decode_symbol_dict function in jbig2_symbol_dict.c in libjbig2dec.a
during operation on a crafted .jb2 file (CVE-2017-7885).
Artifex jbig2dec allows out-of-bounds writes because of an integer
overflow in the jbig2_build_huffman_table function in jbig2_huffman.c
during operations on a crafted JBIG2 file, leading to a denial of service
(application crash) or possibly execution of arbitrary code
(CVE-2017-7975).
Artifex jbig2dec allows out-of-bounds writes and reads because of an
integer overflow in the jbig2_image_compose function in jbig2_image.c
during operations on a crafted .jb2 file, leading to a denial of service
(application crash) (CVE-2017-7976).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | jbig2dec | 0 (affected), 0.13-1.mga5 (unaffected) | — |
Aliases
Transitive aliases
CVE-2017-5951CVE-2016-10219CVE-2016-7976GSD-2016-7978EUVD-2016-8826GHSA-2gqv-9xv4-43w4VVD-MAGEIA-2017-133EUVD-2017-16945GHSA-chwm-vq5f-3r66EUVD-2017-15021EUVD-2016-1404EUVD-2016-8824EUVD-2016-10405CVE-2016-10218CVE-2016-10217GHSA-458q-p5fc-j68hGHSA-9v96-pr6j-ghxcGHSA-64cw-wmc5-j274GHSA-rhh2-326j-w4xrEUVD-2016-1402GHSA-9rxh-wvvf-hh9jEUVD-2017-16860GHSA-8rh8-m25j-rhmpCVE-2016-10220CNVD-2016-09583GHSA-3g8x-c82p-r7gjEUVD-2016-1403GHSA-h247-9cp2-w26hCNVD-2017-06032GHSA-jp8p-fj2v-5982GHSA-vf87-jj8q-h556GSD-2017-7885CNVD-2017-06134CVE-2016-7978CVE-2017-7207GSD-2016-7976EUVD-2017-16946GSD-2017-7975EUVD-2016-1405EUVD-2017-16243CNVD-2016-09581
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.