Input validation error in JasPer - CVE-2008-3520
Published: October 2, 2008 / Updated: August 4, 2020
Vulnerability identifier: #VU33786
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2008-3520
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
Affected software
JasPer
Gentoo Linux
Fedora
Slackware Linux
jasper (Alpine package)
jasper
Gentoo Linux
Fedora
Slackware Linux
jasper (Alpine package)
jasper
How to mitigate CVE-2008-3520
Install update from vendor's website.
JasPer - update to 1.900.2
jasper (Alpine package) - addressed in versions 1.900.1-r4, 1.900.1-r5
jasper - update to 1.900.1-13.el5
jasper (Alpine package) - addressed in versions 1.900.1-r4, 1.900.1-r5
jasper - update to 1.900.1-13.el5
External References
- http://bugs.gentoo.org/show_bug.cgi?id=222819
- http://rhn.redhat.com/errata/RHSA-2015-0698.html
- http://secunia.com/advisories/33173
- http://secunia.com/advisories/34391
- http://security.gentoo.org/glsa/glsa-200812-18.xml
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:142
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:144
- http://www.mandriva.com/security/advisories?name=MDVSA-2009:164
- http://www.redhat.com/support/errata/RHSA-2009-0012.html
- http://www.securityfocus.com/bid/31470
- http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.538606
- http://www.ubuntu.com/usn/USN-742-1
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45621
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10141