Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8137

Опубликовано: 18 дек. 2014
Источник: redhat
CVSS2: 5.1
EPSS Средний

Описание

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

A double free flaw was found in the way JasPer parsed ICC color profiles in JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmNot affected
Red Hat Enterprise Linux 6jasperFixedRHSA-2014:202118.12.2014
Red Hat Enterprise Linux 7jasperFixedRHSA-2014:202118.12.2014
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor6FixedRHSA-2015:171303.09.2015
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor7FixedRHSA-2015:171303.09.2015
RHEV 3.X Hypervisor and Agents for RHEL-7rhev-hypervisor7FixedRHSA-2015:171303.09.2015
RHEV Manager version 3.5spice-client-msiFixedRHSA-2015:069818.03.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1173157jasper: double-free in in jas_iccattrval_destroy() (oCERT-2014-012)

EPSS

Процентиль: 97%
0.31457
Средний

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

nvd
больше 10 лет назад

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

debian
больше 10 лет назад

Double free vulnerability in the jas_iccattrval_destroy function in Ja ...

github
больше 3 лет назад

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

suse-cvrf
больше 10 лет назад

Security update for jasper

EPSS

Процентиль: 97%
0.31457
Средний

5.1 Medium

CVSS2