6.8
CVSSv2

CVE-2014-8137

Published: 24/12/2014 Updated: 05/01/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and previous versions allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jasper project jasper

redhat enterprise linux 6.0

redhat enterprise linux 7.0

Vendor Advisories

Synopsis Important: jasper security update Type/Severity Security Advisory: Important Topic Updated jasper packages that fix three security issues are now availablefor Red Hat Enterprise Linux 6 and 7Red Hat Product Security has rated this update as having Important securityimpact Common Vulnerability Sco ...
Debian Bug report logs - #773463 jasper: CVE-2014-8137 CVE-2014-8138 Package: src:jasper; Maintainer for src:jasper is Roland Stigge <stigge@antcomde>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 18 Dec 2014 17:33:01 UTC Severity: grave Tags: patch, security, upstream Found in version jasper/1 ...
Ghostscript could be made to crash or run programs as your login if it opened a specially crafted file ...
JasPer could be made to crash or run programs as your login if it opened a specially crafted file ...
Multiple off-by-one flaws, leading to heap-based buffer overflows, were found in the way JasPer decoded JPEG 2000 image files A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code (CVE-2014-9029) A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 image files A ...
A double free flaw was found in the way JasPer parsed ICC color profiles in JPEG 2000 image files A specially crafted file could cause an application using JasPer to crash or, possibly, execute arbitrary code ...
Double free vulnerability in the jas_iccattrval_destroy function in JasPer 19001 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file ...