Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-9029

Опубликовано: 08 дек. 2014
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:jasper_project:jasper:*:*:*:*:*:*:*:*
Версия до 1.900.1 (включая)

EPSS

Процентиль: 97%
0.32606
Средний

7.5 High

CVSS2

Дефекты

CWE-189

Связанные уязвимости

ubuntu
больше 10 лет назад

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

redhat
больше 10 лет назад

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

debian
больше 10 лет назад

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jp ...

github
больше 3 лет назад

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

oracle-oval
больше 10 лет назад

ELSA-2014-2021: jasper security update (IMPORTANT)

EPSS

Процентиль: 97%
0.32606
Средний

7.5 High

CVSS2

Дефекты

CWE-189