Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file, a different vulnerability than CVE-2014-8137.
CVSS Details
- CVSS 3.1 Base Score: 7.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jasper | Sep 20, 2017 | Apr 13, 2016 |
| Amazon_linux | — | Upgrade jasper | Jun 7, 2017 | Apr 13, 2016 |
| Centos_linux | — | Upgrade jasper-libsUpgrade jasper-develUpgrade jasperUpgrade jasper-debuginfoUpgrade jasper-utils | May 19, 2017 | Apr 13, 2016 |
| Debian | — | Upgrade jasper | Mar 8, 2016 | Mar 6, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade jasper-libs | Nov 30, 2017 | Apr 13, 2016 |
| Huawei Euleros 2_0_sp2 | — | Upgrade jasper-libs | Nov 30, 2017 | Apr 13, 2016 |
| Oracle_linux | — | Upgrade jasper-utilsUpgrade jasperUpgrade jasper-develUpgrade jasper-libs | May 9, 2017 | Mar 3, 2016 |
| Redhat_linux | — | Upgrade jasper-develUpgrade jasperUpgrade jasper-libsUpgrade jasper-debuginfoUpgrade jasper-utils | May 9, 2017 | Apr 13, 2016 |
| Suse | — | Upgrade libjasper-develUpgrade libjasper4Upgrade libjasperUpgrade libjasper-32bitUpgrade libjasper1-32bitUpgrade libjasper-x86Upgrade libjasper1 | Nov 5, 2016 | Apr 13, 2016 |
| Ubuntu | — | Upgrade libjasper1 | Mar 3, 2016 | Mar 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub