Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8157

Опубликовано: 21 янв. 2015
Источник: redhat
CVSS2: 6.8
EPSS Низкий

Описание

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

An off-by-one flaw, leading to a heap-based buffer overflow, was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmWill not fix
Red Hat Enterprise Linux 6jasperFixedRHSA-2015:007422.01.2015
Red Hat Enterprise Linux 7jasperFixedRHSA-2015:007422.01.2015
RHEV Manager version 3.5spice-client-msiFixedRHSA-2015:069818.03.2015

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-193->CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1179282jasper: dec->numtiles off-by-one check in jpc_dec_process_sot() (oCERT-2015-001)

EPSS

Процентиль: 90%
0.05895
Низкий

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

nvd
больше 10 лет назад

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

debian
больше 10 лет назад

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 ...

github
больше 3 лет назад

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

suse-cvrf
больше 10 лет назад

Security update for jasper

EPSS

Процентиль: 90%
0.05895
Низкий

6.8 Medium

CVSS2