Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-5221

Опубликовано: 20 авг. 2015
Источник: redhat
CVSS3: 7
CVSS2: 5.1
EPSS Низкий

Описание

Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmNot affected
Red Hat Enterprise Linux 6jasperFixedRHSA-2017:120809.05.2017
Red Hat Enterprise Linux 7jasperFixedRHSA-2017:120809.05.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=1255710jasper: use-after-free and double-free flaws in mif_process_cmpt()

EPSS

Процентиль: 81%
0.0219
Низкий

7 High

CVSS3

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

CVSS3: 5.5
nvd
около 9 лет назад

Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

CVSS3: 5.5
debian
около 9 лет назад

Use-after-free vulnerability in the mif_process_cmpt function in libja ...

CVSS3: 5.5
github
около 4 лет назад

Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.

suse-cvrf
больше 9 лет назад

Security update for jasper

EPSS

Процентиль: 81%
0.0219
Низкий

7 High

CVSS3

5.1 Medium

CVSS2