Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-19543

Опубликовано: 13 июл. 2018
Источник: redhat
CVSS3: 3.3

Описание

An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

A vulnerability was found in Jasper due to a heap-based buffer overflow caused by improper bounds checking in the jp2_decode function within libjasper/jp2/jp2_dec.c, an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a buffer overflow that could execute arbitrary code on the system or cause the application to crash.

Отчет

This vulnerability was rated as LOW severity because it requires the victim to open a specially crafted file, it may lead to a buffer overflow that could cause the application to crash, it does not pose a direct threat of system compromise.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmNot affected
Red Hat Enterprise Linux 6jasperWill not fix
Red Hat Enterprise Linux 7jasperFix deferred
Red Hat Enterprise Linux 8jasperFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1658795jasper: heap-based buffer over-read in jp2_decode() in jp2_dec.c

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

CVSS3: 7.8
nvd
больше 7 лет назад

An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

CVSS3: 7.8
debian
больше 7 лет назад

An issue was discovered in JasPer 2.0.14. There is a heap-based buffer ...

CVSS3: 7.8
github
больше 4 лет назад

An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.

suse-cvrf
почти 6 лет назад

Security update for jasper

3.3 Low

CVSS3