CVE-2008-3520
published 2008-10-02CVE-2008-3520: Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer…
PriorityP430critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
3.21%
86.8th percentile
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 8.64~dfsg-2 | 8.64~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-2 | 8.64~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-2 | 8.64~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-2 | 8.64~dfsg-2 |
| debian | ghostscript | < ghostscript 8.64~dfsg-2 (bookworm) | ghostscript 8.64~dfsg-2 (bookworm) |
| debian | netpbm-free | < ghostscript 8.64~dfsg-2 (bookworm) | ghostscript 8.64~dfsg-2 (bookworm) |
| jasper_project | jasper | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3LOW
vendor_redhat9.3CRITICAL
vendor_ubuntu9.3CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jasper: integer overflow in the jas_matrix_create() function
vendor_redhat·2015-12-24·CVSS 9.3
CVE-2015-8751 [CRITICAL] CWE-190 jasper: integer overflow in the jas_matrix_create() function
jasper: integer overflow in the jas_matrix_create() function
Integer overflow in the jas_matrix_create function in JasPer allows context-dependent attackers to have unspecified impact via a crafted JPEG 2000 image, related to integer multiplication for memory allocation.
Statement: This issue did not affect the versions of jasper as shipped with Red Hat Enterprise Linux 6 and 7 as it was already fixed via CVE-2008-3520.
Package: netpbm (Red Hat Enterprise Linux 5) - Not affected
Package: jasper (Red Hat Enterprise Linux 6) - Not affected
Package: jasper (Red Hat Enterprise Linux 7) - Not affected
Package: mingw-virt-viewer (Red Hat Enterprise Virtualization 3) - Not affected
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2012-01-04·CVSS 9.3
CVE-2008-3520 [CRITICAL] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that Ghostscript did not correctly handle memory
allocation when parsing certain malformed JPEG-2000 images. If a user or
automated system were tricked into opening a specially crafted image, an
attacker could cause a denial of service and possibly execute arbitrary
code with user privileges. (CVE-2008-3520)
It was discovered that Ghostscript did not correctly handle certain
formatting operations when parsing JPEG-2000 images. If a user or automated
system were tricked into opening a specially crafted image, an attacker
could cause a denial of service and possibly execute arbitrary code with
user privileges. (CVE-2008-3522)
Ubuntu
JasPer vulnerabilities
vendor_ubuntu·2009-03-19·CVSS 9.3
CVE-2008-3520 [CRITICAL] JasPer vulnerabilities
Title: JasPer vulnerabilities
Summary: JasPer vulnerabilities
It was discovered that JasPer did not correctly handle memory allocation
when parsing certain malformed JPEG2000 images. If a user were tricked into
opening a specially crafted image with an application that uses libjasper,
an attacker could cause a denial of service and possibly execute arbitrary
code with the user's privileges. (CVE-2008-3520)
It was discovered that JasPer created temporary files in an insecure way.
Local users could exploit a race condition and cause a denial of service in
libjasper applications.
(CVE-2008-3521)
It was discovered that JasPer did not correctly handle certain formatting
operations. If a user were tricked into opening a specially crafted image
with an application that uses libjasper, an atta
Red Hat
jasper: multiple integer overflows in jas_alloc calls
vendor_redhat·2008-09-08·CVSS 9.3
CVE-2008-3520 [CRITICAL] CWE-190 jasper: multiple integer overflows in jas_alloc calls
jasper: multiple integer overflows in jas_alloc calls
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
Debian
CVE-2008-3520: ghostscript - Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attac...
vendor_debian·2008·CVSS 9.3
CVE-2008-3520 [CRITICAL] CVE-2008-3520: ghostscript - Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attac...
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
Scope: local
bookworm: resolved (fixed in 8.64~dfsg-2)
bullseye: resolved (fixed in 8.64~dfsg-2)
forky: resolved (fixed in 8.64~dfsg-2)
sid: resolved (fixed in 8.64~dfsg-2)
trixie: resolved (fixed in 8.64~dfsg-2)
GHSA
GHSA-83j4-67f2-p565: Multiple integer overflows in JasPer 1
ghsa_unreviewed·2022-05-02
CVE-2008-3520 [HIGH] GHSA-83j4-67f2-p565: Multiple integer overflows in JasPer 1
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
OSV
CVE-2008-3520: Multiple integer overflows in JasPer 1
osv·2008-10-02·CVSS 9.3
CVE-2008-3520 [CRITICAL] CVE-2008-3520: Multiple integer overflows in JasPer 1
Multiple integer overflows in JasPer 1.900.1 might allow context-dependent attackers to have an unknown impact via a crafted image file, related to integer multiplication for memory allocation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-6850 jasper: uninitialized pointer use in jp2_cdef_destroy()
bugzilla·2017-03-21·CVSS 9.3
CVE-2017-6850 [CRITICAL] CVE-2017-6850 jasper: uninitialized pointer use in jp2_cdef_destroy()
CVE-2017-6850 jasper: uninitialized pointer use in jp2_cdef_destroy()
Null pointer dereference vulnerability in jp2_cdef_destroy was found.
Upstream bug:
https://github.com/mdadams/jasper/issues/112
Upstream patch:
https://github.com/mdadams/jasper/commit/e96fc4fdd525fa0ede28074a7e2b1caf94b58b0d
Reference:
http://seclists.org/oss-sec/2017/q1/191
Discussion:
Created jasper tracking bugs for this issue:
Affects: epel-5 [bug 1434466]
Affects: fedora-all [bug 1434464]
Created mingw-jasper tracking bugs for this issue:
Affects: epel-7 [bug 1434465]
Affects: fedora-all [bug 1434467]
---
The problem here was that the jp2_box_get() function, unlike jp2_box_create(), did not properly initialize members of the jp2_box_t structure after allocating it. If some error occurred while readi
Bugzilla
CVE-2016-9396 CVE-2016-9397 CVE-2016-9398 CVE-2016-9399 CVE-2017-1000050 CVE-2017-13745 CVE-2017-13746 CVE-2017-13747 CVE-2017-13748 CVE-2017-13749 CVE-2017-13750 CVE-2017-13751 CVE-2017-13752 CVE-201
bugzilla·2017-03-21·CVSS 7.5
CVE-2016-9396 [HIGH] CVE-2016-9396 CVE-2016-9397 CVE-2016-9398 CVE-2016-9399 CVE-2017-1000050 CVE-2017-13745 CVE-2017-13746 CVE-2017-13747 CVE-2017-13748 CVE-2017-13749 CVE-2017-13750 CVE-2017-13751 CVE-2017-13752 CVE-201
CVE-2016-9396 CVE-2016-9397 CVE-2016-9398 CVE-2016-9399 CVE-2017-1000050 CVE-2017-13745 CVE-2017-13746 CVE-2017-13747 CVE-2017-13748 CVE-2017-13749 CVE-2017-13750 CVE-2017-13751 CVE-2017-13752 CVE-2017-14132 ... jasper: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant t
Bugzilla
CVE-2016-8882 jasper: uninitialized tile->pi pointer use in JPC decoder
bugzilla·2016-10-26·CVSS 9.3
CVE-2016-8882 [CRITICAL] CVE-2016-8882 jasper: uninitialized tile->pi pointer use in JPC decoder
CVE-2016-8882 jasper: uninitialized tile->pi pointer use in JPC decoder
Null pointer access due to improper initialization was found in jpc_pi_destroy.
Upstream patch:
https://github.com/mdadams/jasper/commit/69a1439a5381e42b06ec6a06ed2675eb793babee
CVE assignment:
http://seclists.org/oss-sec/2016/q4/216
Discussion:
Created mingw-jasper tracking bugs for this issue:
Affects: fedora-all [bug 1388874]
Affects: epel-7 [bug 1388876]
---
Created jasper tracking bugs for this issue:
Affects: fedora-all [bug 1388873]
Affects: epel-5 [bug 1388875]
---
Upstream bug report:
https://github.com/mdadams/jasper/issues/30
The problem was in the jpc_dec_process_siz() function, which did not initialize tile->pi. Later on, when tile data was freed, non-NULL tile->pi led to the call of jpc_pi_
Bugzilla
CVE-2016-8887 jasper: uninitialized pointer use in jp2_box_get()
bugzilla·2016-10-26·CVSS 9.3
CVE-2016-8887 [CRITICAL] CVE-2016-8887 jasper: uninitialized pointer use in jp2_box_get()
CVE-2016-8887 jasper: uninitialized pointer use in jp2_box_get()
Null pointer dereference vulnerability in jp2_colr_destroy in jp2_cod.c was found.
Upstream patch:
https://github.com/mdadams/jasper/commit/e24bdc716c3327b067c551bc6cfb97fd2370358d
CVE assignment:
http://seclists.org/oss-sec/2016/q4/215
Discussion:
Created mingw-jasper tracking bugs for this issue:
Affects: fedora-all [bug 1388874]
Affects: epel-7 [bug 1388876]
---
Created jasper tracking bugs for this issue:
Affects: fedora-all [bug 1388873]
Affects: epel-5 [bug 1388875]
---
This isn't actually a NULL pointer dereference issue, but rather a use of uninitialized pointer. In the jp2_box_get() function, a variable box of type jp2_box_t is allocated using jas_malloc(). Data parsed from a read file is stored in the s
Bugzilla
CVE-2015-8751 jasper: integer overflow in the jas_matrix_create() function
bugzilla·2016-01-08·CVSS 9.3
CVE-2015-8751 [CRITICAL] CVE-2015-8751 jasper: integer overflow in the jas_matrix_create() function
CVE-2015-8751 jasper: integer overflow in the jas_matrix_create() function
An integer overflow flaw was found in the way the JasPer's library jas_matrix_create() function parsed certain JPEG 2000 image files. A specially crafted file could cause an application using JasPer to crash.
This was originally filed against Fedora as bug 1294039, which includes a PoC for this issue.
CVE assignment:
http://seclists.org/oss-sec/2016/q1/44
Discussion:
Created mingw-jasper tracking bugs for this issue:
Affects: fedora-all [bug 1296951]
Affects: epel-7 [bug 1296953]
---
Created jasper tracking bugs for this issue:
Affects: fedora-all [bug 1294039]
Affects: epel-5 [bug 1296952]
---
This was fixed upstream in 1.900.4, see bug 461476 comment 23.
---
Statement:
This issue did not affect the
Bugzilla
CVE-2008-3520 CVE-2008-3522 Multiple jasper vulnerabilities
bugzilla·2009-10-22·CVSS 9.3
CVE-2008-3520 [CRITICAL] CVE-2008-3520 CVE-2008-3522 Multiple jasper vulnerabilities
CVE-2008-3520 CVE-2008-3522 Multiple jasper vulnerabilities
This is an automatically created tracking bug! It was created to ensure that one or more security vulnerabilities are fixed in all affected branches.
For comments that are specific to the vulnerability please use bugs filed against "Security Response" product referenced in "Blocks" field.
bug #461476: CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls
bug #461478: CVE-2008-3522 jasper: possible buffer overflow in jas_stream_printf()
When creating a Bodhi update request, please include the bug IDs of the respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available and only close this bug once all affected Fedora versions are fixed.
Bodhi updat
Bugzilla
CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls
bugzilla·2008-09-08·CVSS 9.3
CVE-2008-3520 [CRITICAL] CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls
CVE-2008-3520 jasper: multiple integer overflows in jas_alloc calls
Marc Espie and Christian Weisgerber of the OpenBSD project identified multiple possible integer overflows in jasper. Problems occur in jas_malloc calls, where integer overflows may result in an insufficient memory allocation, leading to a heap based buffer overflow.
OpenBSD jasper library patches:
http://www.openbsd.org/cgi-bin/cvsweb/ports/graphics/jasper/patches/
Discussion:
Created attachment 316077
OpenBSD patch
This patch introduces jas_alloc[23] and jas_realloc2 functions and replaces all jas_malloc calls with argument containing multiplication of 2 or 3 values. In multiple cases, such change is not necessary (product is guaranteed not to overflow), and it was not further investigated in which cases overflow is
http://bugs.gentoo.org/show_bug.cgi?id=222819http://rhn.redhat.com/errata/RHSA-2015-0698.htmlhttp://secunia.com/advisories/33173http://secunia.com/advisories/34391http://security.gentoo.org/glsa/glsa-200812-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:142http://www.mandriva.com/security/advisories?name=MDVSA-2009:144http://www.mandriva.com/security/advisories?name=MDVSA-2009:164http://www.redhat.com/support/errata/RHSA-2009-0012.htmlhttp://www.securityfocus.com/bid/31470http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.538606http://www.ubuntu.com/usn/USN-742-1https://exchange.xforce.ibmcloud.com/vulnerabilities/45621https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10141http://bugs.gentoo.org/show_bug.cgi?id=222819http://rhn.redhat.com/errata/RHSA-2015-0698.htmlhttp://secunia.com/advisories/33173http://secunia.com/advisories/34391http://security.gentoo.org/glsa/glsa-200812-18.xmlhttp://www.mandriva.com/security/advisories?name=MDVSA-2009:142http://www.mandriva.com/security/advisories?name=MDVSA-2009:144http://www.mandriva.com/security/advisories?name=MDVSA-2009:164http://www.redhat.com/support/errata/RHSA-2009-0012.htmlhttp://www.securityfocus.com/bid/31470http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.538606http://www.ubuntu.com/usn/USN-742-1https://exchange.xforce.ibmcloud.com/vulnerabilities/45621https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10141
2008-10-02
Published