[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-8137Date: (C)2015-01-02   (M)2023-12-28


Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.8
Exploit Score: 8.6
Impact Score: 6.4
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: NONE
Confidentiality: PARTIAL
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
SECTRACK-1033459
SECUNIA-61747
SECUNIA-62311
SECUNIA-62615
SECUNIA-62619
BID-71742
DSA-3106
MDVSA-2015:012
MDVSA-2015:159
RHSA-2014:2021
RHSA-2015:0698
RHSA-2015:1713
SSA:2015-302-02
USN-2483-1
USN-2483-2
http://advisories.mageia.org/MGASA-2014-0539.html
http://packetstormsecurity.com/files/129660/JasPer-1.900.1-Double-Free-Heap-Overflow.html
https://www.ocert.org/advisories/ocert-2014-012.html
openSUSE-SU-2015:0038
openSUSE-SU-2015:0039
openSUSE-SU-2015:0042

CPE    2
cpe:/a:jasper_project:jasper
cpe:/o:redhat:enterprise_linux:7.0
OVAL    20
oval:org.secpod.oval:def:108115
oval:org.secpod.oval:def:108108
oval:org.secpod.oval:def:22314
oval:org.secpod.oval:def:108184
...

© SecPod Technologies