FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-3520

This CVE name corresponds to:

Entered Topic
2013-04-18 jasper -- buffer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-3520
Phase Assigned(20080807)

Description

Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.

References

Source Reference
MISC http://bugs.gentoo.org/show_bug.cgi?id=222819
GENTOO GLSA-200812-18
MANDRIVA MDVSA-2009:142
MANDRIVA MDVSA-2009:144
MANDRIVA MDVSA-2009:164
REDHAT RHSA-2009:0012
REDHAT RHSA-2015:0698
UBUNTU USN-742-1
BID 31470
OVAL oval:org.mitre.oval:def:10141
SECUNIA 33173
SECUNIA 34391
XF jasper-image-file-bo(45621)