4.3
CVSSv2

CVE-2007-2721

Published: 16/05/2007 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The jpc_qcx_getcompparms function in jpc/jpc_cs.c for the JasPer JPEG-2000 library (libjasper) prior to 1.900 allows remote user-assisted malicious users to cause a denial of service (crash) and possibly corrupt the heap via malformed image files, as originally demonstrated using imagemagick convert.

Vulnerable Product Search on Vulmon Subscribe to Product

jasper jpeg-2000 jasper jpeg-2000

Vendor Advisories

Synopsis Moderate: netpbm security update Type/Severity Security Advisory: Moderate Topic Updated netpbm packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4 and 5This update has been rated as having moderate security impact by the RedHat Security Response Team ...
It was discovered that Jasper did not correctly handle corrupted JPEG2000 images By tricking a user into opening a specially crafted JPG, a remote attacker could cause the application using libjasper to crash, resulting in a denial of service ...
USN-501-1 fixed vulnerabilities in Jasper This update provides the corresponding update for the Jasper internal to Ghostscript ...