Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-9029

Опубликовано: 08 дек. 2014
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 7.5

Описание

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

РелизСтатусПримечание
devel

not-affected

uses system jasper
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [uses system jasper]]
lucid

released

8.71.dfsg.1-0ubuntu5.6
precise

not-affected

uses system jasper
trusty

not-affected

uses system jasper
trusty/esm

DNE

trusty was not-affected [uses system jasper]
upstream

needs-triage

utopic

not-affected

uses system jasper

Показывать по

РелизСтатусПримечание
devel

not-affected

1.900.1-debian1-2.2
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [1.900.1-14ubuntu3.1]]
lucid

ignored

end of life
precise

released

1.900.1-13ubuntu0.1
trusty

released

1.900.1-14ubuntu3.1
trusty/esm

DNE

trusty was released [1.900.1-14ubuntu3.1]
upstream

released

1.900.1-debian1-2.2
utopic

released

1.900.1-debian1-2ubuntu0.1

Показывать по

EPSS

Процентиль: 97%
0.32606
Средний

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

nvd
больше 10 лет назад

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

debian
больше 10 лет назад

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jp ...

github
больше 3 лет назад

Multiple off-by-one errors in the (1) jpc_dec_cp_setfromcox and (2) jpc_dec_cp_setfromrgn functions in jpc/jpc_dec.c in JasPer 1.900.1 and earlier allow remote attackers to execute arbitrary code via a crafted jp2 file, which triggers a heap-based buffer overflow.

oracle-oval
больше 10 лет назад

ELSA-2014-2021: jasper security update (IMPORTANT)

EPSS

Процентиль: 97%
0.32606
Средний

7.5 High

CVSS2