PT-2014-8799 · Jasper+5 · Jasper+5

Published

2014-12-04

·

Updated

2024-06-15

·

CVE-2014-9029

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions JasPer versions 1.900.1 and earlier
Description The issue is caused by multiple off-by-one errors in the jpc dec cp setfromcox and jpc dec cp setfromrgn functions. This allows remote attackers to execute arbitrary code via a crafted jp2 file, triggering a heap-based buffer overflow.
Recommendations For JasPer versions 1.900.1 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2474
CESA-2014_2021
CVE-2014-9029
DLA-101-1
DSA-3089-1
MGASA-2014-0514
OPENSUSE-SU-2024:10281-1
RHSA-2014:2021
RHSA-2014_2021
RHSA-2015:0698
SUSE-SU-2015_0207-1
USN-2434-1
USN-2434-2

Affected Products

Alt Linux
Centos
Jasper
Red Hat
Suse
Ubuntu