Описание
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.
A double free flaw was found in the way JasPer parsed ICC color profiles in JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | netpbm | Not affected | ||
Red Hat Enterprise Linux 6 | jasper | Fixed | RHSA-2014:2021 | 18.12.2014 |
Red Hat Enterprise Linux 7 | jasper | Fixed | RHSA-2014:2021 | 18.12.2014 |
RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor6 | Fixed | RHSA-2015:1713 | 03.09.2015 |
RHEV 3.X Hypervisor and Agents for RHEL-6 | rhev-hypervisor7 | Fixed | RHSA-2015:1713 | 03.09.2015 |
RHEV 3.X Hypervisor and Agents for RHEL-7 | rhev-hypervisor7 | Fixed | RHSA-2015:1713 | 03.09.2015 |
RHEV Manager version 3.5 | spice-client-msi | Fixed | RHSA-2015:0698 | 18.03.2015 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.1 Medium
CVSS2
Связанные уязвимости
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.
Double free vulnerability in the jas_iccattrval_destroy function in Ja ...
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.
EPSS
5.1 Medium
CVSS2