Lucene search

K
cloudfoundryCloud FoundryCFOUNDRY:2D5257B7ED095BDE30D255D140E627B8
HistoryMar 24, 2016 - 12:00 a.m.

USN-2919-1 JasPer vulnerabilities | Cloud Foundry

2016-03-2400:00:00
Cloud Foundry
www.cloudfoundry.org
29

0.034 Low

EPSS

Percentile

91.5%

USN-2919-1 JasPer vulnerabilities

Medium

Vendor

Ubuntu, JasPer

Versions Affected

  • Ubuntu 14.04 LTS

Description

Jacob Baines discovered that JasPer incorrectly handled ICC color profiles in JPEG-2000 image files. If a user were tricked into opening a specially crafted JPEG-2000 image file, a remote attacker could cause JasPer to crash or possibly execute arbitrary code with user privileges. (CVE-2016-1577)

Tyler Hicks discovered that JasPer incorrectly handled memory when processing JPEG-2000 image files. If a user were tricked into opening a specially crafted JPEG-2000 image file, a remote attacker could cause JasPer to consume memory, resulting in a denial of service. (CVE-2016-2116)

Affected Products and Versions

_Severity is medium unless otherwise noted.
_

  • All versions of Cloud Foundry rootfs prior to 1.41.0

Mitigation

Users of affected versions should apply the following mitigation:

  • The Cloud Foundry project recommends that Cloud Foundry deployments run with rootfs version 1.41.0 and higher

Credit

Jacob Baines, Tyler Hicks

References