PT-2008-1066 · Bryan Henderson+3 · Netpbm+5

Published

2008-10-02

·

Updated

2017-09-29

·

CVE-2008-3520

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions JasPer versions prior to 1.900.1-r3 netpbm-progs versions prior to 10.35 netpbm versions prior to 10.35 netpbm-devel versions prior to 10.35
Description The issue involves multiple vulnerabilities in the mentioned packages, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The vulnerabilities in JasPer are related to multiple integer overflows, which might allow context-dependent attackers to have an unknown impact via a crafted image file.
Recommendations For JasPer versions prior to 1.900.1-r3, update to version 1.900.1-r3 or later. For netpbm-progs versions prior to 10.35, update to version 10.35 or later. For netpbm versions prior to 10.35, update to version 10.35 or later. For netpbm-devel versions prior to 10.35, update to version 10.35 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2474
BDU:2015-06432
BDU:2015-06433
BDU:2015-06435
BDU:2015-06436
BDU:2015-06438
BDU:2015-06439
BDU:2015-08357
BDU:2015-08358
BDU:2015-08359
BDU:2015-08360
BDU:2015-08361
BDU:2015-08362
BDU:2015-09350
CVE-2008-3520
RHSA-2009:0012
RHSA-2009_0012
RHSA-2015:0698

Affected Products

Alt Linux
Jasper
Red Hat
Netpbm
Netpbm-Devel
Netpbm-Progs