Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-8751

Опубликовано: 24 дек. 2015
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

Отчет

This issue did not affect the versions of jasper as shipped with Red Hat Enterprise Linux 6 and 7 as it was already fixed via CVE-2008-3520.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmNot affected
Red Hat Enterprise Linux 6jasperNot affected
Red Hat Enterprise Linux 7jasperNot affected
Red Hat Enterprise Virtualization 3mingw-virt-viewerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1296949jasper: integer overflow in the jas_matrix_create() function

EPSS

Процентиль: 75%
0.00859
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 6 лет назад

Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

CVSS3: 8.8
nvd
почти 6 лет назад

Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

CVSS3: 8.8
debian
почти 6 лет назад

Integer overflow in the jas_matrix_create function in JasPer allows co ...

CVSS3: 8.8
github
больше 3 лет назад

Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.

EPSS

Процентиль: 75%
0.00859
Низкий

4.3 Medium

CVSS2