CVE-2011-4516
published 2011-12-15CVE-2011-4516: Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code…
PriorityP344medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
10.62%
95.3th percentile
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | ghostscript | >= 0 < 8.64~dfsg-2 | 8.64~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-2 | 8.64~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-2 | 8.64~dfsg-2 |
| artifex | ghostscript | >= 0 < 8.64~dfsg-2 | 8.64~dfsg-2 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | ghostscript | < ghostscript 8.64~dfsg-2 (bookworm) | ghostscript 8.64~dfsg-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| jasper_project | jasper | — | — |
| oracle | outside_in_technology | — | — |
| oracle | outside_in_technology | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_ubuntu9.3CRITICAL
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
vendor_redhat·2016-10-17·CVSS 6.8
CVE-2016-8880 [MEDIUM] CWE-122 jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
jasper: heap buffer overflow in jpc_dec_cp_setfromcox() (rejected duplicate of CVE-2011-4516)
[REJECTED CVE] A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 compressed image files. An attacker could create a malicious JPEG 2000 compressed image file that, when opened, would cause applications that use JasPer (such as Nautilus) to crash or, potentially, execute arbitrary code.
Statement: This flaw was found to be a duplicate of CVE-2011-4516. Please see https://access.redhat.com/security/cve/CVE-2011-4516 for information about affected products and security errata.
Package: netpbm (Red Hat Enterprise Linux 5) - Not affected
Package: jasper (Red Hat Enterprise Linux 6) - Not affected
Package: jasper (Red Hat Enterprise Linux 7) - Not affected
Package: mi
Ubuntu
Ghostscript vulnerabilities
vendor_ubuntu·2012-01-04·CVSS 9.3
CVE-2008-3520 [CRITICAL] Ghostscript vulnerabilities
Title: Ghostscript vulnerabilities
Summary: Ghostscript could be made to crash or run programs as your login if it
opened a specially crafted file.
It was discovered that Ghostscript did not correctly handle memory
allocation when parsing certain malformed JPEG-2000 images. If a user or
automated system were tricked into opening a specially crafted image, an
attacker could cause a denial of service and possibly execute arbitrary
code with user privileges. (CVE-2008-3520)
It was discovered that Ghostscript did not correctly handle certain
formatting operations when parsing JPEG-2000 images. If a user or automated
system were tricked into opening a specially crafted image, an attacker
could cause a denial of service and possibly execute arbitrary code with
user privileges. (CVE-2008-3522)
Ubuntu
JasPer vulnerabilities
vendor_ubuntu·2011-12-20
CVE-2011-4516 JasPer vulnerabilities
Title: JasPer vulnerabilities
Summary: JasPer could be made to crash or run programs as your login if it opened a
specially crafted file.
Jonathan Foote discovered that JasPer incorrectly handled certain malformed
JPEG-2000 image files. If a user were tricked into opening a specially
crafted JPEG-2000 image file, a remote attacker could cause JasPer to crash
or possibly execute arbitrary code with user privileges.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409)
vendor_redhat·2011-12-08·CVSS 6.8
CVE-2011-4516 [MEDIUM] CWE-122 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409)
jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409)
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
A heap-based buffer overflow flaw was found in the way JasPer decoded JPEG 2000 compressed image files. An attacker could create a malicious JPEG 2000 compressed image file that, when opened, would cause applications that use JasPer (such as Nautilus) to crash or, potentially, execute arbitrary code.
Debian
CVE-2011-4516: ghostscript - Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc...
vendor_debian·2011·CVSS 6.8
CVE-2011-4516 [MEDIUM] CVE-2011-4516: ghostscript - Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc...
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
Scope: local
bookworm: resolved (fixed in 8.64~dfsg-2)
bullseye: resolved (fixed in 8.64~dfsg-2)
forky: resolved (fixed in 8.64~dfsg-2)
sid: resolved (fixed in 8.64~dfsg-2)
trixie: resolved (fixed in 8.64~dfsg-2)
GHSA
GHSA-v5vh-4qg5-mqc3: Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs
ghsa_unreviewed·2022-05-17
CVE-2011-4516 [MEDIUM] CWE-119 GHSA-v5vh-4qg5-mqc3: Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
OSV
CVE-2011-4516: Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs
osv·2011-12-15·CVSS 6.8
CVE-2011-4516 [MEDIUM] CVE-2011-4516: Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs
Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted numrlvls value in a coding style default (COD) marker segment in a JPEG2000 file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-4]
bugzilla·2011-12-09·CVSS 6.8
CVE-2011-4516 [MEDIUM] CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-4]
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-4]
epel-4 tracking bug for jasper: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
jasper-1.900.1-14.el4 has been submitted as an update for Fedora EPEL 4.
https://admin.fedoraproject.org/updates/jasper-1.900.1-14.el4
---
jasper-1.900.1-14.el4 has been pushed to the Fedora EPEL 4 stable repository. If problems still persist, please make note of it in this bug report.
---
EPEL-4 has reached end of life and is no longer supported.
Please retest your bug against EPEL-5 or EPEL-6 and re-open if t
Bugzilla
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [fedora-all]
bugzilla·2011-12-09·CVSS 6.8
CVE-2011-4516 [MEDIUM] CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [fedora-all]
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://a
Bugzilla
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-5]
bugzilla·2011-12-09·CVSS 6.8
CVE-2011-4516 [MEDIUM] CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-5]
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-5]
epel-5 tracking bug for mingw32-jasper: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
All mingw32 packages have been removed from EPEL-5 as per https://fedorahosted.org/rel-eng/ticket/5977
Bugzilla
CVE-2011-4516 CVE-2011-4517 mingw32-jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [fedora-all]
bugzilla·2011-12-09·CVSS 6.8
CVE-2011-4516 [MEDIUM] CVE-2011-4516 CVE-2011-4517 mingw32-jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [fedora-all]
CVE-2011-4516 CVE-2011-4517 mingw32-jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
h
Bugzilla
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-5]
bugzilla·2011-12-09·CVSS 6.8
CVE-2011-4516 [MEDIUM] CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-5]
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409) [epel-5]
epel-5 tracking bug for jasper: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
jasper-1.900.1-14.el5 has been submitted as an update for Fedora EPEL 5.
https://admin.fedoraproject.org/updates/jasper-1.900.1-14.el5
---
jasper-1.900.1-14.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409)
bugzilla·2011-10-20·CVSS 6.8
CVE-2011-4516 [MEDIUM] CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409)
CVE-2011-4516 CVE-2011-4517 jasper: heap buffer overflow flaws lead to arbitrary code execution (CERT VU#887409)
A number of vulnerabilities were found and reported by CERT in JasPer which may allow a remote unauthenticated attacker to execute arbitrary code.
Reference:
http://www.kb.cert.org/vuls/id/887409
Discussion:
There are two overflows here, and they have been assigned the names CVE-2011-4516 and CVE-2011-4517.
---
Acknowledgements:
Red Hat would like to thank Jonathan Foote of the CERT Coordination Center for reporting this issue.
---
This issue affects the version of jasper package as shipped with Red Hat Enterprise Linux 6.
This issue affects the version of netpbm package as shipped with Red Hat Enterprise Linux 4 and 5.
---
Created mingw32-jasper tracking bugs for th
http://lists.fedoraproject.org/pipermail/package-announce/2011-December/071458.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-January/071561.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-12/msg00010.htmlhttp://osvdb.org/77595http://rhn.redhat.com/errata/RHSA-2015-0698.htmlhttp://secunia.com/advisories/47193http://secunia.com/advisories/47306http://secunia.com/advisories/47353http://www-01.ibm.com/support/docview.wss?uid=swg21660640http://www.debian.org/security/2011/dsa-2371http://www.kb.cert.org/vuls/id/887409http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1807.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1811.htmlhttp://www.securityfocus.com/bid/50992http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.538606http://www.ubuntu.com/usn/USN-1315-1https://bugzilla.redhat.com/show_bug.cgi?id=747726http://lists.fedoraproject.org/pipermail/package-announce/2011-December/071458.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-January/071561.htmlhttp://lists.opensuse.org/opensuse-security-announce/2011-12/msg00010.htmlhttp://osvdb.org/77595http://rhn.redhat.com/errata/RHSA-2015-0698.htmlhttp://secunia.com/advisories/47193http://secunia.com/advisories/47306http://secunia.com/advisories/47353http://www-01.ibm.com/support/docview.wss?uid=swg21660640http://www.debian.org/security/2011/dsa-2371http://www.kb.cert.org/vuls/id/887409http://www.oracle.com/technetwork/topics/security/cpujan2012-366304.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1807.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1811.htmlhttp://www.securityfocus.com/bid/50992http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.538606http://www.ubuntu.com/usn/USN-1315-1https://bugzilla.redhat.com/show_bug.cgi?id=747726
2011-12-15
Published