PT-2011-1114 · Netpbm+4 · Netpbm-Progs+6

Jonathan Foote

·

Published

2011-12-09

·

Updated

2024-06-15

·

CVE-2011-4517

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions netpbm-progs versions 10.35.58 netpbm-devel versions 10.35.58 netpbm versions 10.35.58 JasPer versions prior to 1.900.1-r4
Description The issue concerns multiple vulnerabilities in various packages, including netpbm-progs, netpbm-devel, and netpbm, which can lead to disruption of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Additionally, a specific vulnerability in the jpc crg getparms function in libjasper/jpc/jpc cs.c in JasPer 1.900.1 allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code or cause a denial of service via a crafted component registration (CRG) marker segment in a JPEG2000 file.
Recommendations For netpbm-progs version 10.35.58, update to a newer version to mitigate the risk. For netpbm-devel version 10.35.58, update to a newer version to mitigate the risk. For netpbm version 10.35.58, update to a newer version to mitigate the risk. For JasPer versions prior to 1.900.1-r4, update to version 1.900.1-r4 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable packages until a patch is available.

Fix

DoS

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2474
BDU:2015-06434
BDU:2015-06437
BDU:2015-06440
BDU:2015-08581
BDU:2015-08582
BDU:2015-08583
BDU:2015-09443
CESA-2011_1807
CVE-2011-4517
DSA-2371-1
OPENSUSE-SU-2024:10281-1
RHSA-2011:1807
RHSA-2011:1811
RHSA-2011_1807
RHSA-2011_1811
RHSA-2015:0698

Affected Products

Alt Linux
Centos
Jasper
Red Hat
Netpbm
Netpbm-Devel
Netpbm-Progs