FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2008-3522

This CVE name corresponds to:

Entered Topic
2013-04-18 jasper -- buffer overflow

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2008-3522
Phase Assigned(20080807)

Description

Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.

References

Source Reference
MISC http://bugs.gentoo.org/attachment.cgi?id=163282&action=view
MISC http://bugs.gentoo.org/show_bug.cgi?id=222819
GENTOO GLSA-200812-18
MANDRIVA MDVSA-2009:142
MANDRIVA MDVSA-2009:144
MANDRIVA MDVSA-2009:164
REDHAT RHSA-2015:0698
UBUNTU USN-742-1
BID 31470
SECUNIA 33173
SECUNIA 34391
XF jasper-jasstreamprintf-bo(45623)