Lucene search

K
debianDebianDEBIAN:DLA-138-1:982F5
HistoryJan 28, 2015 - 7:03 p.m.

[SECURITY] [DLA 138-1] jasper security update

2015-01-2819:03:39
lists.debian.org
10

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.093 Low

EPSS

Percentile

94.7%

Package : jasper
Version : 1.900.1-7+squeeze4
CVE ID : CVE-2014-8157 CVE-2014-8158
Debian Bug : 775970

An off-by-one flaw, leading to a heap-based buffer overflow
(CVE-2014-8157), and an unrestricted stack memory use flaw
(CVE-2014-8158) were found in JasPer, a library for manipulating
JPEG-2000 files. A specially crafted file could cause an application
using JasPer to crash or, possibly, execute arbitrary code.

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.7 Medium

AI Score

Confidence

Low

0.093 Low

EPSS

Percentile

94.7%