PT-2013-1171 · Centos+4 · Centos+4

Publicado

2013-12-12

·

Atualizado

2021-02-02

·

CVE-2013-6054

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openjpeg versions prior to 1.5.2 openjpeg-1.3 openjpeg-debuginfo-1.3 openjpeg-devel-1.3 openjpeg-libs-1.3
Description The issue affects the openjpeg package in various operating systems, including CentOS, Gentoo Linux, and Red Hat Enterprise Linux. It involves multiple vulnerabilities that can be exploited remotely, potentially leading to breaches of confidentiality, integrity, and availability of protected information. One of the vulnerabilities is a heap-based buffer overflow in OpenJPEG 1.3.
Recommendations For openjpeg versions prior to 1.5.2, update to version 1.5.2 or later. For openjpeg-1.3, openjpeg-debuginfo-1.3, openjpeg-devel-1.3, and openjpeg-libs-1.3, consider disabling the vulnerable components until a patch is available. As a temporary workaround, restrict access to the vulnerable modules to minimize the risk of exploitation.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-2337
ALT-PU-2021-1097
ALT-PU-2021-1197
BDU:2015-06455
BDU:2015-06456
BDU:2015-06457
BDU:2015-06458
BDU:2015-08985
BDU:2015-08986
BDU:2015-08987
BDU:2015-08988
BDU:2015-09772
CESA-2013_1850
CVE-2013-6054
DSA-2808-1
RHSA-2013:1850
RHSA-2013_1850

Produtos afetados

Alt Linux
Centos
Gentoo Linux
Openjpeg
Red Hat