Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8881

Опубликовано: 17 окт. 2016
Источник: redhat
CVSS2: 6.8

Описание

[REJECTED CVE] A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 compressed image files. An attacker could create a malicious JPEG 2000 compressed image file that, when opened, would cause applications that use JasPer (such as Nautilus) to crash or, potentially, execute arbitrary code.

Отчет

This flaw was found to be a duplicate of CVE-2011-4517. Please see https://access.redhat.com/security/cve/CVE-2011-4517 for information about affected products and security errata.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmNot affected
Red Hat Enterprise Linux 6jasperNot affected
Red Hat Enterprise Linux 7jasperNot affected
Red Hat Enterprise Virtualization 3mingw-virt-viewerNot affected

Показывать по

Дополнительная информация

Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1388864jasper: insufficient memory allocation in jpc_crg_getparms() (rejected duplicate of CVE-2011-4517)

6.8 Medium

CVSS2

Связанные уязвимости

ubuntu
около 9 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4517. Reason: This candidate is a duplicate of CVE-2011-4517. Notes: All CVE users should reference CVE-2011-4517 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

nvd
около 9 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4517. Reason: This candidate is a duplicate of CVE-2011-4517. Notes: All CVE users should reference CVE-2011-4517 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

suse-cvrf
около 9 лет назад

Security update for jasper

suse-cvrf
около 9 лет назад

Security update for jasper

suse-cvrf
около 9 лет назад

Security update for jasper

6.8 Medium

CVSS2