Executive Summary



This Alert is flagged as TOP 25 Common Weakness Enumeration from CWE/SANS. For more information, you can read this.
Summary
Title JasPer memory corruption vulnerabilities
Informations
Name VU#887409 First vendor Publication 2011-12-08
Vendor VU-CERT Last vendor Modification 2012-03-28
Severity (Vendor) N/A Revision M

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:M/Au:N/C:P/I:P/A:P)
Cvss Base Score 6.8 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Medium
Cvss Expoit Score 8.6 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

 


This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify

Original Source

Url : http://www.kb.cert.org/vuls/id/887409

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-787 Out-of-bounds Write (CWE/SANS Top 25)

OVAL Definitions

Definition Id: oval:org.mitre.oval:def:15085
 
Oval ID: oval:org.mitre.oval:def:15085
Title: DSA-2371-1 jasper -- buffer overflows
Description: Two buffer overflows were discovered in JasPer, a library for handling JPEG-2000 images, which could lead to the execution of arbitrary code.
Family: unix Class: patch
Reference(s): DSA-2371-1
CVE-2011-4516
CVE-2011-4517
Version: 5
Platform(s): Debian GNU/Linux 6.0
Debian GNU/kFreeBSD 6.0
Product(s): jasper
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:15133
 
Oval ID: oval:org.mitre.oval:def:15133
Title: USN-1317-1 -- Ghostscript vulnerabilities
Description: ghostscript: The GPL Ghostscript PostScript/PDF interpreter Ghostscript could be made to crash or run programs as your login if it opened a specially crafted file.
Family: unix Class: patch
Reference(s): USN-1317-1
CVE-2008-3520
CVE-2008-3522
CVE-2009-3743
CVE-2010-4054
CVE-2011-4516
CVE-2011-4517
Version: 5
Platform(s): Ubuntu 10.10
Ubuntu 8.04
Ubuntu 10.04
Product(s): Ghostscript
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:15246
 
Oval ID: oval:org.mitre.oval:def:15246
Title: USN-1315-1 -- JasPer vulnerabilities
Description: jasper: Library for manipulating JPEG-2000 files JasPer could be made to crash or run programs as your login if it opened a specially crafted file.
Family: unix Class: patch
Reference(s): USN-1315-1
CVE-2011-4516
CVE-2011-4517
Version: 5
Platform(s): Ubuntu 11.04
Ubuntu 11.10
Ubuntu 10.04
Ubuntu 10.10
Product(s): JasPer
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21637
 
Oval ID: oval:org.mitre.oval:def:21637
Title: RHSA-2011:1807: jasper security update (Important)
Description: The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.
Family: unix Class: patch
Reference(s): RHSA-2011:1807-01
CESA-2011:1807
CVE-2011-4516
CVE-2011-4517
Version: 29
Platform(s): Red Hat Enterprise Linux 6
CentOS Linux 6
Product(s): jasper
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:21974
 
Oval ID: oval:org.mitre.oval:def:21974
Title: RHSA-2011:1811: netpbm security update (Important)
Description: The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.
Family: unix Class: patch
Reference(s): RHSA-2011:1811-01
CESA-2011:1811
CVE-2009-4274
CVE-2011-4516
CVE-2011-4517
Version: 42
Platform(s): Red Hat Enterprise Linux 5
CentOS Linux 5
Product(s): netpbm
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:22965
 
Oval ID: oval:org.mitre.oval:def:22965
Title: ELSA-2011:1811: netpbm security update (Important)
Description: The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.
Family: unix Class: patch
Reference(s): ELSA-2011:1811-01
CVE-2009-4274
CVE-2011-4516
CVE-2011-4517
Version: 17
Platform(s): Oracle Linux 5
Product(s): netpbm
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:23679
 
Oval ID: oval:org.mitre.oval:def:23679
Title: ELSA-2011:1807: jasper security update (Important)
Description: The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a heap-based buffer overflow and execute arbitrary code, or cause a denial of service (heap memory corruption), via a crafted component registration (CRG) marker segment in a JPEG2000 file.
Family: unix Class: patch
Reference(s): ELSA-2011:1807-01
CVE-2011-4516
CVE-2011-4517
Version: 13
Platform(s): Oracle Linux 6
Product(s): jasper
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:28114
 
Oval ID: oval:org.mitre.oval:def:28114
Title: DEPRECATED: ELSA-2011-1807 -- jasper security update (important)
Description: [1.900.1-15.1] - CERT VU#887409: heap buffer overflow flaws lead to arbitrary code execution (#749149)
Family: unix Class: patch
Reference(s): ELSA-2011-1807
CVE-2011-4516
CVE-2011-4517
Version: 4
Platform(s): Oracle Linux 6
Product(s): jasper
Definition Synopsis:

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1
Application 2
Os 4
Os 1
Os 2
Os 1
Os 1
Os 2
Os 1

OpenVAS Exploits

Date Description
2012-07-30 Name : CentOS Update for jasper CESA-2011:1807 centos6
File : nvt/gb_CESA-2011_1807_jasper_centos6.nasl
2012-07-30 Name : CentOS Update for netpbm CESA-2011:1811 centos4 x86_64
File : nvt/gb_CESA-2011_1811_netpbm_centos4_x86_64.nasl
2012-07-30 Name : CentOS Update for netpbm CESA-2011:1811 centos5 x86_64
File : nvt/gb_CESA-2011_1811_netpbm_centos5_x86_64.nasl
2012-07-09 Name : RedHat Update for jasper RHSA-2011:1807-01
File : nvt/gb_RHSA-2011_1807-01_jasper.nasl
2012-03-19 Name : Fedora Update for jasper FEDORA-2011-16966
File : nvt/gb_fedora_2011_16966_jasper_fc16.nasl
2012-02-12 Name : Gentoo Security Advisory GLSA 201201-10 (JasPer)
File : nvt/glsa_201201_10.nasl
2012-01-09 Name : Fedora Update for jasper FEDORA-2011-16955
File : nvt/gb_fedora_2011_16955_jasper_fc15.nasl
2012-01-09 Name : Ubuntu Update for ghostscript USN-1317-1
File : nvt/gb_ubuntu_USN_1317_1.nasl
2011-12-23 Name : Ubuntu Update for jasper USN-1315-1
File : nvt/gb_ubuntu_USN_1315_1.nasl
2011-12-19 Name : Mandriva Update for jasper MDVSA-2011:189 (jasper)
File : nvt/gb_mandriva_MDVSA_2011_189.nasl
2011-12-16 Name : CentOS Update for netpbm CESA-2011:1811 centos4 i386
File : nvt/gb_CESA-2011_1811_netpbm_centos4_i386.nasl
2011-12-16 Name : CentOS Update for netpbm CESA-2011:1811 centos5 i386
File : nvt/gb_CESA-2011_1811_netpbm_centos5_i386.nasl
2011-12-16 Name : RedHat Update for netpbm RHSA-2011:1811-01
File : nvt/gb_RHSA-2011_1811-01_netpbm.nasl

Open Source Vulnerability Database (OSVDB)

Id Description
77596 JasPer src/libjasper/jpc/jpc_cs.c jpc_crg_getparms() Function CRG Marker Segm...

77595 JasPer src/libjasper/jpc/jpc_cs.c jpc_cox_getcompparms() Function COD Market ...

Snort® IPS/IDS

Date Description
2016-03-25 Oracle Outside-In invalid CRG segment memory corruption attempt
RuleID : 37852 - Revision : 1 - Type : FILE-OTHER
2016-03-25 Oracle Outside-In invalid CRG segment memory corruption attempt
RuleID : 37851 - Revision : 1 - Type : FILE-OTHER
2014-01-10 Oracle Outside In JPEG COC parameter buffer overflow attempt
RuleID : 24718 - Revision : 8 - Type : FILE-IMAGE
2014-01-10 Oracle Outside In JPEG COD parameter buffer overflow attempt
RuleID : 24717 - Revision : 8 - Type : FILE-IMAGE
2014-01-10 Oracle Outside In JPEG COC parameter buffer overflow attempt
RuleID : 24716 - Revision : 8 - Type : FILE-IMAGE
2014-01-10 Oracle Outside In JPEG COD parameter buffer overflow attempt
RuleID : 24715 - Revision : 8 - Type : FILE-IMAGE
2014-01-10 Oracle Outside In JPEG COC parameter buffer overflow attempt
RuleID : 24714 - Revision : 8 - Type : FILE-IMAGE
2014-01-10 Oracle Outside In JPEG COD parameter buffer overflow attempt
RuleID : 24713 - Revision : 8 - Type : FILE-IMAGE
2014-01-10 Oracle Outside In JPEG COC parameter buffer overflow attempt
RuleID : 24712 - Revision : 8 - Type : FILE-IMAGE
2014-01-10 Oracle Outside In JPEG COD parameter buffer overflow attempt
RuleID : 24711 - Revision : 8 - Type : FILE-IMAGE

Nessus® Vulnerability Scanner

Date Description
2016-11-07 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2016-1270.nasl - Type : ACT_GATHER_INFO
2015-10-30 Name : The remote Slackware host is missing a security update.
File : Slackware_SSA_2015-302-02.nasl - Type : ACT_GATHER_INFO
2015-03-20 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2015-0698.nasl - Type : ACT_GATHER_INFO
2015-01-19 Name : The remote Solaris system is missing a security patch for third-party software.
File : solaris11_ghostscript_20120710.nasl - Type : ACT_GATHER_INFO
2014-12-17 Name : The remote Fedora host is missing a security update.
File : fedora_2014-16961.nasl - Type : ACT_GATHER_INFO
2014-12-17 Name : The remote Fedora host is missing a security update.
File : fedora_2014-17027.nasl - Type : ACT_GATHER_INFO
2014-12-17 Name : The remote Fedora host is missing a security update.
File : fedora_2014-17032.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : suse_11_4_jasper-111214.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : suse_11_3_jasper-111214.nasl - Type : ACT_GATHER_INFO
2014-06-13 Name : The remote openSUSE host is missing a security update.
File : openSUSE-2011-87.nasl - Type : ACT_GATHER_INFO
2013-09-04 Name : The remote Amazon Linux AMI host is missing a security update.
File : ala_ALAS-2011-29.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2011-1811.nasl - Type : ACT_GATHER_INFO
2013-07-12 Name : The remote Oracle Linux host is missing one or more security updates.
File : oraclelinux_ELSA-2011-1807.nasl - Type : ACT_GATHER_INFO
2013-04-18 Name : The remote FreeBSD host is missing a security-related update.
File : freebsd_pkg_8ff84335a7da11e2b3f5003067c2616f.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20111209_jasper_on_SL6_x.nasl - Type : ACT_GATHER_INFO
2012-08-01 Name : The remote Scientific Linux host is missing one or more security updates.
File : sl_20111212_netpbm_on_SL4_x.nasl - Type : ACT_GATHER_INFO
2012-03-28 Name : An archiving application installed on the remote host has multiple vulnerabil...
File : symantec_enterprise_vault_sym12-004.nasl - Type : ACT_GATHER_INFO
2012-01-24 Name : The remote Gentoo host is missing one or more security-related patches.
File : gentoo_GLSA-201201-10.nasl - Type : ACT_GATHER_INFO
2012-01-12 Name : The remote Debian host is missing a security-related update.
File : debian_DSA-2371.nasl - Type : ACT_GATHER_INFO
2012-01-05 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1317-1.nasl - Type : ACT_GATHER_INFO
2012-01-03 Name : The remote Fedora host is missing a security update.
File : fedora_2011-16966.nasl - Type : ACT_GATHER_INFO
2012-01-03 Name : The remote Fedora host is missing a security update.
File : fedora_2011-16955.nasl - Type : ACT_GATHER_INFO
2011-12-23 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2011-1807.nasl - Type : ACT_GATHER_INFO
2011-12-21 Name : The remote Ubuntu host is missing a security-related patch.
File : ubuntu_USN-1315-1.nasl - Type : ACT_GATHER_INFO
2011-12-19 Name : The remote Mandriva Linux host is missing one or more security updates.
File : mandriva_MDVSA-2011-189.nasl - Type : ACT_GATHER_INFO
2011-12-15 Name : The remote SuSE 10 host is missing a security-related patch.
File : suse_jasper-7878.nasl - Type : ACT_GATHER_INFO
2011-12-13 Name : The remote SuSE 11 host is missing one or more security updates.
File : suse_11_jasper-111207.nasl - Type : ACT_GATHER_INFO
2011-12-13 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2011-1811.nasl - Type : ACT_GATHER_INFO
2011-12-13 Name : The remote CentOS host is missing one or more security updates.
File : centos_RHSA-2011-1811.nasl - Type : ACT_GATHER_INFO
2011-12-09 Name : The remote Red Hat host is missing one or more security updates.
File : redhat-RHSA-2011-1807.nasl - Type : ACT_GATHER_INFO

Alert History

If you want to see full details history, please login or register.
0
1
Date Informations
2014-12-18 13:25:37
  • Multiple Updates
2014-02-17 12:08:15
  • Multiple Updates