PT-2008-1066 · Bryan Henderson+3 · Netpbm+5
Published
2008-10-02
·
Updated
2017-09-29
·
CVE-2008-3520
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
JasPer versions prior to 1.900.1-r3
netpbm-progs versions prior to 10.35
netpbm versions prior to 10.35
netpbm-devel versions prior to 10.35
Description
The issue involves multiple vulnerabilities in the mentioned packages, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities in JasPer are related to multiple integer overflows, which might allow context-dependent attackers to have an unknown impact via a crafted image file.
Recommendations
For JasPer versions prior to 1.900.1-r3, update to version 1.900.1-r3 or later.
For netpbm-progs versions prior to 10.35, update to version 10.35 or later.
For netpbm versions prior to 10.35, update to version 10.35 or later.
For netpbm-devel versions prior to 10.35, update to version 10.35 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Jasper
Red Hat
Netpbm
Netpbm-Devel
Netpbm-Progs