Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:23710
HistoryApr 10, 2020 - 12:34 a.m.

Arbitrary Code Execution

2020-04-1000:34:17
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17

EPSS

0.058

Percentile

93.4%

netpbm is vulnerable to arbitrary code execution. The vulnerability exists as an input validation flaw and multiple integer overflows were discovered in the JasPer library providing support for JPEG-2000 image format and used in the jpeg2ktopam and pamtojpeg2k converters. An attacker could create a carefully-crafted JPEG file which could cause jpeg2ktopam to crash or, possibly, execute arbitrary code as the user running jpeg2ktopam.

References