PT-2014-1908 · Openjpeg · Openjpeg

Raphael Geissert

·

Publicado

2014-01-06

·

Atualizado

2020-09-09

·

CVE-2013-6887

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OpenJPEG versions prior to 1.5.2
Description The issue allows remote attackers to cause problems, including denial of service, via unspecified vectors that trigger errors such as NULL pointer dereferences and division-by-zero. Exploitation of the vulnerabilities can lead to disruption of confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-09772
CVE-2013-6887
MGASA-2014-0005

Produtos afetados

Openjpeg