Lucene search

K
cve[email protected]CVE-2014-8158
HistoryJan 26, 2015 - 3:59 p.m.

CVE-2014-8158

2015-01-2615:59:09
CWE-119
web.nvd.nist.gov
41
cve-2014-8158
stack-based buffer overflow
jasper
denial of service
arbitrary code execution
jpeg 2000
nvd

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

High

0.079 Low

EPSS

Percentile

94.3%

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted JPEG 2000 image.

Affected configurations

NVD
Node
jasper_projectjasperRange1.900.1
Node
debiandebian_linuxMatch7.0
Node
redhatenterprise_linuxMatch6.0
OR
redhatenterprise_linuxMatch7.0
Node
opensuseopensuseMatch13.1
OR
opensuseopensuseMatch13.2

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

6.3 Medium

AI Score

Confidence

High

0.079 Low

EPSS

Percentile

94.3%