10
CVSSv2

CVE-2008-3522

Published: 02/10/2008 Updated: 08/08/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Buffer overflow in the jas_stream_printf function in libjasper/base/jas_stream.c in JasPer 1.900.1 might allow context-dependent malicious users to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise virtualization 3.5

jasper project jasper 1.900.1

Vendor Advisories

Debian Bug report logs - #501021 jasper: CVE-2008-352[0-2] multiple integer overflows in jas_alloc calls Package: jasper; Maintainer for jasper is Roland Stigge <stigge@antcomde>; Reported by: Nico Golde <nion@debianorg> Date: Fri, 3 Oct 2008 12:24:01 UTC Severity: grave Tags: patch, security Fixed in version jas ...
It was discovered that JasPer did not correctly handle memory allocation when parsing certain malformed JPEG2000 images If a user were tricked into opening a specially crafted image with an application that uses libjasper, an attacker could cause a denial of service and possibly execute arbitrary code with the user’s privileges (CVE-2008-3520) ...
Ghostscript could be made to crash or run programs as your login if it opened a specially crafted file ...
Several security issues have been discovered in Ghostscript, a GPL PostScript/PDF interpreter, which might lead to the execution of arbitrary code if a user processes a malformed PDF or Postscript file For the stable distribution (lenny), these problems have been fixed in version 862dfsg1-32lenny4 For the unstable distribution (sid), these pr ...
Buffer overflow in the jas_stream_printf function in libjasper/base/jas_streamc in JasPer 19001 might allow context-dependent attackers to have an unknown impact via vectors related to the mif_hdr_put function and use of vsprintf that might lead to arbitrary code execution ...