PT-2008-1095 · Jasper+2 · Jasper+2
Christian Weisgerber
+1
·
Publicado
2008-10-02
·
Atualizado
2024-06-15
·
CVE-2008-3522
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JasPer versions prior to 1.900.1-r3
Description
The issue concerns multiple vulnerabilities in the JasPer package, which can be exploited remotely, potentially leading to breaches in confidentiality, integrity, and availability of protected information. A buffer overflow in the
jas stream printf function in libjasper/base/jas stream.c may allow attackers to have an unknown impact via vectors related to the mif hdr put function and the use of vsprintf.Recommendations
For JasPer versions prior to 1.900.1-r3, update to version 1.900.1-r3 or later to resolve the issue. As a temporary workaround, consider restricting access to the
jas stream printf function until a patch is available. Avoid using the mif hdr put function and the vsprintf function in the affected API endpoints until the issue is resolved.Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Jasper
Suse