FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2014-8138

This CVE name corresponds to:

Entered Topic
2016-02-20 jasper -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2014-8138
Phase Assigned(20141010)

Description

Heap-based buffer overflow in the jp2_decode function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 file.

References

Source Reference
MISC https://www.ocert.org/advisories/ocert-2014-012.html
MISC http://packetstormsecurity.com/files/129660/JasPer-1.900.1-Double-Free-Heap-Overflow.html
CONFIRM http://advisories.mageia.org/MGASA-2014-0539.html
DEBIAN DSA-3106
MANDRIVA MDVSA-2015:012
MANDRIVA MDVSA-2015:159
REDHAT RHSA-2014:2021
REDHAT RHSA-2015:0698
SUSE openSUSE-SU-2015:0038
SUSE openSUSE-SU-2015:0039
SUSE openSUSE-SU-2015:0042
UBUNTU USN-2483-1
UBUNTU USN-2483-2
SECUNIA 61747
SECUNIA 62311
SECUNIA 62615
SECUNIA 62619