Vulnerability Name: | CVE-2008-3520 (CCN-45621) | ||||||||||||||||||||||||||||||||
Assigned: | 2008-09-08 | ||||||||||||||||||||||||||||||||
Published: | 2008-09-08 | ||||||||||||||||||||||||||||||||
Updated: | 2017-09-29 | ||||||||||||||||||||||||||||||||
Summary: | Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.0 Medium (REDHAT Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-189 CWE-190 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||||||||||
References: | Source: CCN Type: Gentoo Bugzilla Bug 222819 media-libs/jasper <1.900.1-r2 multiple vulnerabilities (CVE-2008-{3520,3521,3522}) Source: MISC Type: Patch http://bugs.gentoo.org/show_bug.cgi?id=222819 Source: MITRE Type: CNA CVE-2008-3520 Source: CCN Type: RHSA-2009-0012 Moderate: netpbm security update Source: REDHAT Type: UNKNOWN RHSA-2015:0698 Source: SECUNIA Type: UNKNOWN 33173 Source: SECUNIA Type: UNKNOWN 34391 Source: GENTOO Type: UNKNOWN GLSA-200812-18 Source: CCN Type: ASA-2009-060 netpbm security update (RHSA-2009-0012) Source: CCN Type: JasPer Web page The JasPer Project Home Page Source: CCN Type: GLSA-200812-18 JasPer: User-assisted execution of arbitrary code Source: MANDRIVA Type: UNKNOWN MDVSA-2009:142 Source: MANDRIVA Type: UNKNOWN MDVSA-2009:144 Source: MANDRIVA Type: UNKNOWN MDVSA-2009:164 Source: REDHAT Type: UNKNOWN RHSA-2009:0012 Source: BID Type: Patch 31470 Source: CCN Type: BID-31470 JasPer 1.900.1 Multiple Vulnerabilities Source: SLACKWARE Type: UNKNOWN SSA:2015-302-02 Source: CCN Type: USN-742-1 JasPer vulnerabilities Source: UBUNTU Type: UNKNOWN USN-742-1 Source: XF Type: UNKNOWN jasper-image-file-bo(45621) Source: XF Type: UNKNOWN jasper-image-file-bo(45621) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10141 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |