Lucene search

K
cve[email protected]CVE-2014-8157
HistoryJan 26, 2015 - 3:59 p.m.

CVE-2014-8157

2015-01-2615:59:04
CWE-189
web.nvd.nist.gov
60
cve-2014-8157
remote attack
denial of service
execute arbitrary code
jpeg 2000
buffer overflow

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

High

0.093 Low

EPSS

Percentile

94.7%

Off-by-one error in the jpc_dec_process_sot function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image, which triggers a heap-based buffer overflow.

Affected configurations

NVD
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2
Node
debiandebian_linuxMatch7.0
Node
redhatenterprise_linuxMatch6.0
OR
redhatenterprise_linuxMatch7.0
Node
jasper_projectjasperRange1.900.1

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.4 Medium

AI Score

Confidence

High

0.093 Low

EPSS

Percentile

94.7%