Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8138

Опубликовано: 18 дек. 2014
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmWill not fix
Red Hat Enterprise Linux 6jasperFixedRHSA-2014:202118.12.2014
Red Hat Enterprise Linux 7jasperFixedRHSA-2014:202118.12.2014
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor6FixedRHSA-2015:171303.09.2015
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor7FixedRHSA-2015:171303.09.2015
RHEV 3.X Hypervisor and Agents for RHEL-7rhev-hypervisor7FixedRHSA-2015:171303.09.2015
RHEV Manager version 3.5spice-client-msiFixedRHSA-2015:069818.03.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1173162jasper: heap overflow in jp2_decode() (oCERT-2014-012)

EPSS

Процентиль: 90%
0.05895
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

nvd
больше 10 лет назад

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

debian
больше 10 лет назад

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900. ...

github
больше 3 лет назад

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

suse-cvrf
больше 10 лет назад

Security update for jasper

EPSS

Процентиль: 90%
0.05895
Низкий

6.8 Medium

CVSS2