Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9262

Опубликовано: 06 нояб. 2016
Источник: redhat
CVSS3: 7
CVSS2: 5.1
EPSS Низкий

Описание

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmWill not fix
Red Hat Enterprise Virtualization 3mingw-virt-viewerWill not fix
Red Hat Enterprise Linux 6jasperFixedRHSA-2017:120809.05.2017
Red Hat Enterprise Linux 7jasperFixedRHSA-2017:120809.05.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-681
https://bugzilla.redhat.com/show_bug.cgi?id=1393882jasper: integer truncation in jas_image_cmpt_create()

EPSS

Процентиль: 62%
0.00433
Низкий

7 High

CVSS3

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

CVSS3: 5.5
nvd
больше 8 лет назад

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

CVSS3: 5.5
debian
больше 8 лет назад

Multiple integer overflows in the (1) jas_realloc function in base/jas ...

CVSS3: 5.5
github
больше 3 лет назад

Multiple integer overflows in the (1) jas_realloc function in base/jas_malloc.c and (2) mem_resize function in base/jas_stream.c in JasPer before 1.900.22 allow remote attackers to cause a denial of service via a crafted image, which triggers use after free vulnerabilities.

suse-cvrf
больше 8 лет назад

Security update for jasper

EPSS

Процентиль: 62%
0.00433
Низкий

7 High

CVSS3

5.1 Medium

CVSS2