CVE-2011-4516
jasper - buffer overflows
EPSS 10.6%
描述
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
如何修補 CVE-2011-4516
要修補 CVE-2011-4516,請將受影響套件升級到下列已修補版本。
- Debian/ghostscript—升級至 8.64~dfsg-2 或更新版本
- Debian/jasper—升級至 1.900.1-7+squeeze1 或更新版本
CVE-2011-4516 正在被利用嗎?
中等 — EPSS 為 10.6%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 8.64~dfsg-2
- from 0, < 1.900.1-7+squeeze1