9.3
CVSSv2

CVE-2008-3520

Published: 02/10/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple integer overflows in JasPer 1.900.1 might allow context-dependent malicious users to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.

Vulnerable Product Search on Vulmon Subscribe to Product

jasper project jasper 1.900.1

Vendor Advisories

Synopsis Moderate: netpbm security update Type/Severity Security Advisory: Moderate Topic Updated netpbm packages that fix several security issues are now availablefor Red Hat Enterprise Linux 4 and 5This update has been rated as having moderate security impact by the RedHat Security Response Team ...
Debian Bug report logs - #501021 jasper: CVE-2008-352[0-2] multiple integer overflows in jas_alloc calls Package: jasper; Maintainer for jasper is Roland Stigge <stigge@antcomde>; Reported by: Nico Golde <nion@debianorg> Date: Fri, 3 Oct 2008 12:24:01 UTC Severity: grave Tags: patch, security Fixed in version jas ...
It was discovered that JasPer did not correctly handle memory allocation when parsing certain malformed JPEG2000 images If a user were tricked into opening a specially crafted image with an application that uses libjasper, an attacker could cause a denial of service and possibly execute arbitrary code with the user’s privileges (CVE-2008-3520) ...
Ghostscript could be made to crash or run programs as your login if it opened a specially crafted file ...
Multiple possible integer overflows have been discovered in jasper occurring in jas_malloc calls, where integer overflows may result in an insufficient memory allocation, leading to a heap based buffer overflow ...