Описание
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
Отчет
This vulnerability was rated as LOW severity because it could allow a attacker to execute arbitrary code or crash the application, it doesn’t directly compromise the system.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 5 | netpbm | Out of support scope | ||
| Red Hat Enterprise Linux 6 | jasper | Out of support scope | ||
| Red Hat Enterprise Linux 7 | jasper | Will not fix | ||
| Red Hat Enterprise Linux 8 | jasper | Will not fix |
Показывать по
10
Дополнительная информация
Статус:
Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1664878jasper: heap-based buffer over-read in jp2_encode()
EPSS
Процентиль: 76%
0.00967
Низкий
5.5 Medium
CVSS3
Связанные уязвимости
CVSS3: 6.5
ubuntu
около 7 лет назад
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
CVSS3: 6.5
nvd
около 7 лет назад
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
CVSS3: 6.5
debian
около 7 лет назад
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer o ...
CVSS3: 6.5
github
больше 3 лет назад
jp2_encode in jp2/jp2_enc.c in JasPer 2.0.14 has a heap-based buffer over-read.
EPSS
Процентиль: 76%
0.00967
Низкий
5.5 Medium
CVSS3