Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-2963

Опубликовано: 20 июл. 2022
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

A vulnerability found in jasper. A memory leak bug occurs in the cmdopts_parse function, possibly causing a crash or segmentation fault.

Отчет

Red Hat has determined this vulnerability to be of moderate impact as the memory leak occurs when cmdline parsing fails and causes the process to terminate right away without releasing the memory, leading to the leak. It would take repeated invocations to exhaust system memory and potentially cause service degradation over time. Within regulated environments, a combination of the following controls acts as a significant barrier to successfully exploiting a CWE-401: Missing Release of Memory after Effective Lifetime vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. The platform enforces hardening guidelines to apply the most restrictive configurations necessary for operational requirements. Baseline and configuration setting controls ensure secure system and software configurations, while least functionality reduces the attack surface and minimizes the risk of resource exhaustion from memory leaks. The environment employs malicious code protections such as IDS/IPS and antimalware solutions to detect threats and provide real-time visibility into memory usage, helping prevent memory management issues before they lead to system crashes or exhaustion. Event logs are collected and analyzed for correlation, monitoring, alerting, and retention, supporting the detection of abnormal memory usage patterns that may indicate potential leaks. Static code analysis and peer reviews enforce strong input validation and error handling, reducing the risk of input-based denial-of-service (DoS) attacks. Finally, memory protection mechanisms such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR) are implemented to strengthen defenses against memory allocation vulnerabilities.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8jasperWill not fix
Red Hat Enterprise Linux 9jasperWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2118587jasper: memory leaks in function cmdopts_parse

EPSS

Процентиль: 39%
0.00174
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

CVSS3: 7.5
nvd
больше 3 лет назад

A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.

CVSS3: 7.5
debian
больше 3 лет назад

A vulnerability found in jasper. This security vulnerability happens b ...

suse-cvrf
больше 3 лет назад

Security update for jasper

suse-cvrf
больше 3 лет назад

Security update for jasper

EPSS

Процентиль: 39%
0.00174
Низкий

7.5 High

CVSS3