7.2
CVSSv2

CVE-2008-3521

Published: 02/10/2008 Updated: 07/11/2023
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in the jas_stream_tmpfile function in libjasper/base/jas_stream.c in JasPer 1.900.1 allows local users to cause a denial of service (program exit) by creating the appropriate tmp.XXXXXXXXXX temporary file, which causes Jasper to exit. NOTE: this was originally reported as a symlink issue, but this was incorrect. NOTE: some vendors dispute the severity of this issue, but it satisfies CVE's requirements for inclusion.

Vulnerable Product Search on Vulmon Subscribe to Product

jasper project jasper 1.900.1

Vendor Advisories

Debian Bug report logs - #501021 jasper: CVE-2008-352[0-2] multiple integer overflows in jas_alloc calls Package: jasper; Maintainer for jasper is Roland Stigge <stigge@antcomde>; Reported by: Nico Golde <nion@debianorg> Date: Fri, 3 Oct 2008 12:24:01 UTC Severity: grave Tags: patch, security Fixed in version jas ...
It was discovered that JasPer did not correctly handle memory allocation when parsing certain malformed JPEG2000 images If a user were tricked into opening a specially crafted image with an application that uses libjasper, an attacker could cause a denial of service and possibly execute arbitrary code with the user’s privileges (CVE-2008-3520) ...