Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-20570

Опубликовано: 28 дек. 2018
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

A vulnerability was found in Jasper due to a heap-based buffer overflow caused by improper bounds checking in the jp2_encode function within jp2/jp2_enc.c, an attacker could exploit this flaw by persuading a victim to open a specially crafted file, leading to a buffer overflow that could execute arbitrary code on the system or cause the application to crash.

Отчет

This vulnerability was rated as LOW severity because it could allow a attacker to execute arbitrary code or crash the application, it doesn’t directly compromise the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5netpbmOut of support scope
Red Hat Enterprise Linux 6jasperOut of support scope
Red Hat Enterprise Linux 7jasperWill not fix
Red Hat Enterprise Linux 8jasperWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1664878jasper: heap-based buffer over-read in jp2_encode()

EPSS

Процентиль: 81%
0.02237
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

CVSS3: 6.5
nvd
больше 7 лет назад

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

CVSS3: 6.5
debian
больше 7 лет назад

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer o ...

CVSS3: 6.5
github
больше 4 лет назад

jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.

suse-cvrf
почти 6 лет назад

Security update for jasper

EPSS

Процентиль: 81%
0.02237
Низкий

5.5 Medium

CVSS3