PT-2011-1113 · Netpbm+4 · Netpbm-Progs+6

Jonathan Foote

·

Published

2011-12-09

·

Updated

2024-06-15

·

CVE-2011-4516

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions netpbm-progs versions 10.35.58 netpbm-devel versions 10.35.58 netpbm versions 10.35.58 JasPer versions prior to 1.900.1-r4
Description The issue concerns multiple vulnerabilities in the netpbm and JasPer packages, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Specifically, a heap-based buffer overflow in the jpc cox getcompparms function in libjasper/jpc/jpc cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
Recommendations For netpbm-progs version 10.35.58, update to a version that contains a fix for this issue. For netpbm-devel version 10.35.58, update to a version that contains a fix for this issue. For netpbm version 10.35.58, update to a version that contains a fix for this issue. For JasPer versions prior to 1.900.1-r4, update to version 1.900.1-r4 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable jpc cox getcompparms function in JasPer until a patch is available.

Fix

DoS

RCE

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2474
BDU:2015-06434
BDU:2015-06437
BDU:2015-06440
BDU:2015-08581
BDU:2015-08582
BDU:2015-08583
BDU:2015-09443
CESA-2011_1807
CVE-2011-4516
DSA-2371-1
OPENSUSE-SU-2024:10281-1
RHSA-2011:1807
RHSA-2011:1811
RHSA-2011_1807
RHSA-2011_1811
RHSA-2015:0698

Affected Products

Alt Linux
Centos
Jasper
Red Hat
Netpbm
Netpbm-Devel
Netpbm-Progs