<?xml version="1.0" encoding="utf-8"?>
<glsa id="200701-05">
<title>KDE kfile JPEG info plugin: Denial of Service</title>
The KDE kfile JPEG info plugin of kdegraphics could enter an endless loop
leading to a Denial of Service.
<product type="ebuild">kdegraphics-kfile-plugins</product>
<announced>January 12, 2007</announced>
<revised>January 12, 2007: 01</revised>
<package name="kde-base/kdegraphics-kfile-plugins" auto="yes" arch="*">
<unaffected range="ge">3.5.5-r1</unaffected>
<vulnerable range="lt">3.5.5-r1</vulnerable>
The KDE kfile-info JPEG plugin provides meta-information about JPEG
Marcus Meissner of the SUSE security team discovered a stack overflow
vulnerability in the code processing EXIF information in the kfile JPEG
info plugin.
<impact type="normal">
A remote attacker could entice a user to view a specially crafted JPEG
image with a KDE application like Konqueror or digiKam, leading to a
Denial of Service by an infinite recursion.
There is no known workaround at this time.
All KDE users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose &quot;&gt;=kde-base/kdegraphics-kfile-plugins-3.5.5-r1&quot;</code>
<uri link="">CVE-2006-6297</uri>
