Описание
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.
A flaw in jasper was discovered where an invalid memory write occurred due to the absence of a proper range check in the JPC encoder.
Отчет
The low severity of the jasper flaw stems from its limited impact and difficulty of exploitation. The invalid memory write issue in the JPC encoder is confined to specific conditions and is not easily triggered in real-world scenarios. Furthermore, the vulnerability does not expose critical data.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | jasper | Out of support scope | ||
| Red Hat Enterprise Linux 7 | jasper | Out of support scope | ||
| Red Hat Enterprise Linux 8 | jasper | Fix deferred | ||
| Red Hat Enterprise Linux 9 | jasper | Fix deferred |
Показывать по
Дополнительная информация
Статус:
7.3 High
CVSS3
Связанные уязвимости
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and before allows a local attacker to execute arbitrary code.
An invalid memory write issue in Jasper-Software Jasper v.4.1.1 and be ...
7.3 High
CVSS3