PT-2017-9738 · Jasper+4 · Jasper+4

Gustavo Grieco

·

Publicado

2016-11-10

·

Atualizado

2024-06-15

·

CVE-2016-8690

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions JasPer versions prior to 1.900.5
Description The issue allows remote attackers to cause a denial of service, specifically a NULL pointer dereference, by using a crafted BMP image in an imginfo command. This is due to a problem in the bmp getdata function.
Recommendations For versions prior to 1.900.5, update to version 1.900.5 or later to resolve the issue. As a temporary workaround, consider restricting the use of the bmp getdata function until a patch is available. Avoid using the imginfo command with untrusted BMP images until the issue is resolved.

Exploit

Correção

DoS

NULL Pointer Dereference

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1947
CESA-2017_1208
CVE-2016-8690
DLA-1583-1
MGASA-2017-0474
OPENSUSE-SU-2024:10281-1
RHSA-2017:1208
RHSA-2017_1208
SUSE-SU-2016:2775-1
SUSE-SU-2016:2776-1

Produtos afetados

Alt Linux
Centos
Jasper
Red Hat
Suse