10
CVSSv2

CVE-2013-4289

Published: 18/04/2014 Updated: 09/09/2020
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG prior to 1.5.2 allow remote malicious users to have unspecified impact and vectors, which trigger a heap-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

uclouvain openjpeg

uclouvain openjpeg 1.5

uclouvain openjpeg 1.4

uclouvain openjpeg 1.3

Vendor Advisories

Debian Bug report logs - #722540 openjpeg: CVE-2013-4289 CVE-2013-4290 Package: openjpeg; Maintainer for openjpeg is Debian PhotoTools Maintainers <pkg-phototools-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Thu, 12 Sep 2013 06:03:02 UTC Severity: grave Tags: security Found ...
Multiple integer overflows in lib/openjp3d/jp3dc in OpenJPEG before 152 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflow ...