Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-8886

Опубликовано: 18 окт. 2016
Источник: redhat
CVSS3: 3.3
CVSS2: 4.3
EPSS Низкий

Описание

The jas_malloc function in libjasper/base/jas_malloc.c in JasPer before 1.900.11 allows remote attackers to have unspecified impact via a crafted file, which triggers a memory allocation failure.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmWill not fix
Red Hat Enterprise Linux 6jasperWill not fix
Red Hat Enterprise Linux 7jasperWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=1388880jasper: no upper limit on memory allocations in jas_malloc()

EPSS

Процентиль: 54%
0.00317
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 9 лет назад

The jas_malloc function in libjasper/base/jas_malloc.c in JasPer before 1.900.11 allows remote attackers to have unspecified impact via a crafted file, which triggers a memory allocation failure.

CVSS3: 7.8
nvd
почти 9 лет назад

The jas_malloc function in libjasper/base/jas_malloc.c in JasPer before 1.900.11 allows remote attackers to have unspecified impact via a crafted file, which triggers a memory allocation failure.

CVSS3: 7.8
debian
почти 9 лет назад

The jas_malloc function in libjasper/base/jas_malloc.c in JasPer befor ...

CVSS3: 7.8
github
больше 3 лет назад

The jas_malloc function in libjasper/base/jas_malloc.c in JasPer before 1.900.11 allows remote attackers to have unspecified impact via a crafted file, which triggers a memory allocation failure.

suse-cvrf
около 9 лет назад

Security update for jasper

EPSS

Процентиль: 54%
0.00317
Низкий

3.3 Low

CVSS3

4.3 Medium

CVSS2