Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8138

Опубликовано: 18 дек. 2014
Источник: redhat
CVSS2: 6.8

Описание

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmWill not fix
Red Hat Enterprise Linux 6jasperFixedRHSA-2014:202118.12.2014
Red Hat Enterprise Linux 7jasperFixedRHSA-2014:202118.12.2014
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor6FixedRHSA-2015:171303.09.2015
RHEV 3.X Hypervisor and Agents for RHEL-6rhev-hypervisor7FixedRHSA-2015:171303.09.2015
RHEV 3.X Hypervisor and Agents for RHEL-7rhev-hypervisor7FixedRHSA-2015:171303.09.2015
RHEV Manager version 3.5spice-client-msiFixedRHSA-2015:069818.03.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1173162jasper: heap overflow in jp2_decode() (oCERT-2014-012)

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 11 лет назад

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

nvd
почти 11 лет назад

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

debian
почти 11 лет назад

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900. ...

github
больше 3 лет назад

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

suse-cvrf
почти 11 лет назад

Security update for jasper

6.8 Medium

CVSS2