PT-2007-7508 · Netpbm+2 · Netpbm-Progs+6
Published
1970-01-01
·
Updated
2017-10-11
·
CVE-2007-2721
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
libjasper-dev versions prior to 1.900
netpbm-progs versions 10.25 through 10.35
netpbm versions 10.25 through 10.35
netpbm-devel versions 10.25 through 10.35
libjasper-runtime (affected versions not specified)
libjasper1 (affected versions not specified)
Description
The issue involves multiple vulnerabilities in the mentioned packages, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The jpc qcx getcompparms function in the JasPer JPEG-2000 library is specifically vulnerable to remote user-assisted attacks, potentially causing a denial of service and heap corruption via malformed image files.
Recommendations
For libjasper-dev versions prior to 1.900, update to version 1.900 or later.
For netpbm-progs versions 10.25 through 10.35, update to a version outside of this range.
For netpbm versions 10.25 through 10.35, update to a version outside of this range.
For netpbm-devel versions 10.25 through 10.35, update to a version outside of this range.
For libjasper-runtime and libjasper1, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Libjasper-Dev
Libjasper-Runtime
Libjasper1
Netpbm
Netpbm-Devel
Netpbm-Progs