Описание
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
A vulnerability was found in Jasper due to a heap-based buffer overflow caused by improper bounds checking in the jp2_encode function within jp2/jp2_enc.c, an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a buffer overflow that could execute arbitrary code on the system or cause the application to crash.
Отчет
This vulnerability was rated as LOW severity because it could allow a attacker to execute arbitrary code or crash the application, it doesn’t directly compromise the system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | netpbm | Out of support scope | ||
| Red Hat Enterprise Linux 6 | jasper | Out of support scope | ||
| Red Hat Enterprise Linux 7 | jasper | Will not fix | ||
| Red Hat Enterprise Linux 8 | jasper | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer o ...
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
EPSS
5.5 Medium
CVSS3