Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-8690

Опубликовано: 15 фев. 2017
Источник: debian
EPSS Низкий

Описание

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
jasperremovedpackage
jasperno-dsawheezypackage

Примечания

  • CVE ID for the first and fifth items of https://www.openwall.com/lists/oss-security/2016/08/23/6 post

  • https://blogs.gentoo.org/ago/2016/10/16/jasper-two-null-pointer-dereference-in-bmp_getdata-bmp_dec-c/

  • The original fix is incomplete resulting in two follow ups CVE-2016-8884 and

  • CVE-2016-8885.

EPSS

Процентиль: 61%
0.00421
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command.

CVSS3: 7
redhat
около 9 лет назад

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command.

CVSS3: 5.5
nvd
больше 8 лет назад

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command.

CVSS3: 5.5
github
больше 3 лет назад

The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command.

suse-cvrf
около 9 лет назад

Security update for jasper

EPSS

Процентиль: 61%
0.00421
Низкий