Описание
Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | netpbm | Will not fix | ||
| Red Hat Enterprise Virtualization 3 | mingw-virt-viewer | Affected | ||
| Red Hat Enterprise Linux 6 | jasper | Fixed | RHSA-2017:1208 | 09.05.2017 |
| Red Hat Enterprise Linux 7 | jasper | Fixed | RHSA-2017:1208 | 09.05.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.8 High
CVSS3
6.8 Medium
CVSS2
Связанные уязвимости
Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow.
Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow.
Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in Ja ...
Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow.
EPSS
7.8 High
CVSS3
6.8 Medium
CVSS2