Artifex jbig2dec 0.13 allows out-of-bounds writes and reads because of an integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 file, leading to a denial of service (application crash) or disclosure of sensitive information from process memory.
CVSS Details
- CVSS 3.0 Base Score: 7.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade jbig2dec | May 15, 2017 | Apr 19, 2017 |
| Gentoo Linux | — | Upgrade media-libs/jbig2dec. | Oct 30, 2017 | Apr 19, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Sep 16, 2021 | Apr 19, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade ghostscriptUpgrade ghostscript-cups | Apr 30, 2021 | Apr 19, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade ghostscript-cupsUpgrade ghostscript | Dec 11, 2019 | Apr 19, 2017 |
| Suse | — | Upgrade mupdf-devel-staticUpgrade mupdf | Nov 23, 2017 | Apr 19, 2017 |
| Ubuntu | — | Upgrade libjbig2dec0Upgrade jbig2dec | May 25, 2017 | Apr 19, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub