Lucene search

K
archlinuxArch LinuxASA-201501-23
HistoryJan 27, 2015 - 12:00 a.m.

jasper: arbitrary code execution

2015-01-2700:00:00
Arch Linux
lists.archlinux.org
40

0.975 High

EPSS

Percentile

100.0%

  • CVE-2014-8157 (arbitrary code execution)

Off-by-one error in the jpc_dec_process_sot function allows remote
attackers to cause a denial of service (crash) or possibly execute
arbitrary code via a crafted JPEG 2000 image, which triggers a
heap-based buffer overflow.

  • CVE-2014-8158 (arbitrary code execution)

Multiple stack-based buffer overflows in jpc_qmfb.c allow remote
attackers to cause a denial of service (crash) or possibly execute
arbitrary code via a crafted JPEG 2000 image.

OSVersionArchitecturePackageVersionFilename
anyanyanyjasper<Β 1.900.1-13UNKNOWN