Lucene search

K
cve[email protected]CVE-2014-8137
HistoryDec 24, 2014 - 6:59 p.m.

CVE-2014-8137

2014-12-2418:59:01
web.nvd.nist.gov
49
cve-2014-8137
double free vulnerability
jasper
denial of service
arbitrary code execution
icc color profile
jpeg 2000
image file

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

High

0.156 Low

EPSS

Percentile

96.0%

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

Affected configurations

NVD
Node
jasper_projectjasperRange1.900.1
Node
redhatenterprise_linuxMatch6.0
OR
redhatenterprise_linuxMatch7.0

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

High

0.156 Low

EPSS

Percentile

96.0%