Описание
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
A vulnerability was found in Jasper due to a heap-based buffer overflow caused by improper bounds checking in the jp2_decode function within libjasper/jp2/jp2_dec.c, an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a buffer overflow that could execute arbitrary code on the system or cause the application to crash.
Отчет
This vulnerability was rated as LOW severity because it requires the victim to open a specially crafted file, it may lead to a buffer overflow that could cause the application to crash, it does not pose a direct threat of system compromise.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | netpbm | Not affected | ||
| Red Hat Enterprise Linux 6 | jasper | Will not fix | ||
| Red Hat Enterprise Linux 7 | jasper | Fix deferred | ||
| Red Hat Enterprise Linux 8 | jasper | Fix deferred |
Показывать по
Дополнительная информация
Статус:
3.3 Low
CVSS3
Связанные уязвимости
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer ...
An issue was discovered in JasPer 2.0.14. There is a heap-based buffer over-read of size 8 in the function jp2_decode in libjasper/jp2/jp2_dec.c.
3.3 Low
CVSS3