PT-2011-1113 · Netpbm+4 · Netpbm-Progs+6
Jonathan Foote
·
Publicado
2011-12-09
·
Atualizado
2024-06-15
·
CVE-2011-4516
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
netpbm-progs versions 10.35.58
netpbm-devel versions 10.35.58
netpbm versions 10.35.58
JasPer versions prior to 1.900.1-r4
Description
The issue concerns multiple vulnerabilities in the netpbm and JasPer packages, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, a heap-based buffer overflow in the
jpc cox getcompparms function in libjasper/jpc/jpc cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.Recommendations
For netpbm-progs version 10.35.58, update to a version that contains a fix for this issue.
For netpbm-devel version 10.35.58, update to a version that contains a fix for this issue.
For netpbm version 10.35.58, update to a version that contains a fix for this issue.
For JasPer versions prior to 1.900.1-r4, update to version 1.900.1-r4 or later to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable
jpc cox getcompparms function in JasPer until a patch is available.Correção
DoS
RCE
Buffer Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Jasper
Red Hat
Netpbm
Netpbm-Devel
Netpbm-Progs