Vulnerability Name: | CVE-2016-10249 (CCN-123333) | ||||||||||||||||||||||||
Assigned: | 2016-10-20 | ||||||||||||||||||||||||
Published: | 2016-10-20 | ||||||||||||||||||||||||
Updated: | 2018-01-05 | ||||||||||||||||||||||||
Summary: | Integer overflow in the jpc_dec_tiledecode function in jpc_dec.c in JasPer before 1.900.12 allows remote attackers to have unspecified impact via a crafted image file, which triggers a heap-based buffer overflow. | ||||||||||||||||||||||||
CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) 6.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
6.8 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
| ||||||||||||||||||||||||
Vulnerability Type: | CWE-190 CWE-190 CWE-122 CWE-122 | ||||||||||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2016-10249 Source: DEBIAN Type: UNKNOWN DSA-3827 Source: CCN Type: IBM Security Bulletin T1025260 (PowerKVM) Vulnerabilities in JasPer affect PowerKVM Source: CCN Type: IBM Security Bulletin T1025538 (SmartCloud Entry) Multiple vulnerabilities in coreutils, sudo, jasper, bind, bash, libtirpc, nss and nss-util affect IBM SmartCloud Entry Source: BID Type: UNKNOWN 93838 Source: CCN Type: BID-93838 JasPer 'jpc_dec.c' Remote Heap Buffer Overflow Vulnerability Source: REDHAT Type: UNKNOWN RHSA-2017:1208 Source: CCN Type: agostino's blog, October 23, 2016 jasper: heap-based buffer overflow in jpc_dec_tiledecode (jpc_dec.c) Source: MISC Type: Exploit, Issue Tracking, Patch, Third Party Advisory, VDB Entry https://blogs.gentoo.org/ago/2016/10/23/jasper-heap-based-buffer-overflow-in-jpc_dec_tiledecode-jpc_dec-c/ Source: XF Type: UNKNOWN jasper-cve201610249-bo(123333) Source: CCN Type: JasPer GIT Repository Fixed an integer overflow problem. Source: CONFIRM Type: Patch, Third Party Advisory https://github.com/mdadams/jasper/commit/988f8365f7d8ad8073b6786e433d34c553ecf568 | ||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Configuration RedHat 4: Configuration RedHat 5: Configuration RedHat 6: Configuration RedHat 7: Configuration RedHat 8: Configuration RedHat 9: Configuration RedHat 10: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||
| |||||||||||||||||||||||||
BACK |