Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-8158

Опубликовано: 21 янв. 2015
Источник: redhat
CVSS2: 5.1

Описание

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

An unrestricted stack memory use flaw was found in the way JasPer decoded JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmNot affected
Red Hat Enterprise Linux 6jasperFixedRHSA-2015:007422.01.2015
Red Hat Enterprise Linux 7jasperFixedRHSA-2015:007422.01.2015
RHEV Manager version 3.5spice-client-msiFixedRHSA-2015:069818.03.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1179298jasper: unrestricted stack memory use in jpc_qmfb.c (oCERT-2015-001)

5.1 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

nvd
больше 10 лет назад

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

debian
больше 10 лет назад

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 ...

github
больше 3 лет назад

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

suse-cvrf
больше 10 лет назад

Security update for jasper

5.1 Medium

CVSS2