PT-2011-1114 · Netpbm+4 · Netpbm-Progs+6
Jonathan Foote
·
Published
2011-12-09
·
Updated
2024-06-15
·
CVE-2011-4517
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
netpbm-progs versions 10.35.58
netpbm-devel versions 10.35.58
netpbm versions 10.35.58
JasPer versions prior to 1.900.1-r4
Description
The issue concerns multiple vulnerabilities in various packages, including netpbm-progs, netpbm-devel, and netpbm, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Additionally, a specific vulnerability in the jpc crg getparms function in libjasper/jpc/jpc cs.c in JasPer 1.900.1 allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code or cause a denial of service via a crafted component registration (CRG) marker segment in a JPEG2000 file.
Recommendations
For netpbm-progs version 10.35.58, update to a newer version to mitigate the risk.
For netpbm-devel version 10.35.58, update to a newer version to mitigate the risk.
For netpbm version 10.35.58, update to a newer version to mitigate the risk.
For JasPer versions prior to 1.900.1-r4, update to version 1.900.1-r4 or later to resolve the issue.
As a temporary workaround, consider restricting access to the vulnerable packages until a patch is available.
Fix
DoS
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Jasper
Red Hat
Netpbm
Netpbm-Devel
Netpbm-Progs