PT-2011-1113 · Netpbm+4 · Netpbm-Progs+6

Jonathan Foote

·

Publicado

2011-12-09

·

Atualizado

2024-06-15

·

CVE-2011-4516

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions netpbm-progs versions 10.35.58 netpbm-devel versions 10.35.58 netpbm versions 10.35.58 JasPer versions prior to 1.900.1-r4
Description The issue concerns multiple vulnerabilities in the netpbm and JasPer packages, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, a heap-based buffer overflow in the jpc cox getcompparms function in libjasper/jpc/jpc cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
Recommendations For netpbm-progs version 10.35.58, update to a version that contains a fix for this issue. For netpbm-devel version 10.35.58, update to a version that contains a fix for this issue. For netpbm version 10.35.58, update to a version that contains a fix for this issue. For JasPer versions prior to 1.900.1-r4, update to version 1.900.1-r4 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable jpc cox getcompparms function in JasPer until a patch is available.

Correção

DoS

RCE

Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-2474
BDU:2015-06434
BDU:2015-06437
BDU:2015-06440
BDU:2015-08581
BDU:2015-08582
BDU:2015-08583
BDU:2015-09443
CESA-2011_1807
CVE-2011-4516
DSA-2371-1
OPENSUSE-SU-2024:10281-1
RHSA-2011:1807
RHSA-2011:1811
RHSA-2011_1807
RHSA-2011_1811
RHSA-2015:0698

Produtos afetados

Alt Linux
Centos
Jasper
Red Hat
Netpbm
Netpbm-Devel
Netpbm-Progs