CVE-2012-1499
published 2012-04-11CVE-2012-1499: The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG…
PriorityP348critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
5.14%
91.5th percentile
The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG image, which triggers memory corruption, aka "out-of heap-based buffer write."
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| uclouvain | openjpeg | <= 1.4 | — |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jw58-44xh-h2cf: The JPEG 2000 codec (jp2
ghsa_unreviewed·2022-05-13
CVE-2012-1499 [HIGH] CWE-119 GHSA-jw58-44xh-h2cf: The JPEG 2000 codec (jp2
The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG image, which triggers memory corruption, aka "out-of heap-based buffer write."
Red Hat
openjpeg: Out-of heap-based buffer write by processing palette information in certain JPEG 2000 images
vendor_redhat·2012-03-20·CVSS 9.3
CVE-2012-1499 [CRITICAL] openjpeg: Out-of heap-based buffer write by processing palette information in certain JPEG 2000 images
openjpeg: Out-of heap-based buffer write by processing palette information in certain JPEG 2000 images
The JPEG 2000 codec (jp2.c) in OpenJPEG before 1.5 allows remote attackers to execute arbitrary code via a crafted palette index in a CMAP record of a JPEG image, which triggers memory corruption, aka "out-of heap-based buffer write."
Statement: Not Vulnerable. This issue did not affect the version of openjpeg as shipped with Red Hat Enterprise Linux 6.
Package: openjpeg (Red Hat Enterprise Linux 6) - Not affected
Red Hat
xchat: Heap-based buffer overflow by processing UTF-8 line from server containing characters outside BMP
vendor_redhat·2012-01-17·CVSS 9.8
CVE-2012-0828 [CRITICAL] CWE-172 xchat: Heap-based buffer overflow by processing UTF-8 line from server containing characters outside BMP
xchat: Heap-based buffer overflow by processing UTF-8 line from server containing characters outside BMP
Heap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial of service (xchat client crash) or execute arbitrary code via a UTF-8 line from server containing characters outside of the Basic Multilingual Plane (BMP).
Statement: Not vulnerable. This issue did not affect the versions of xchat as shipped
with Red Hat Enterprise Linux 4, 5, and 6.
Package: xchat (Red Hat Enterprise Linux 4) - Not affected
Package: xchat (Red Hat Enterprise Linux 5) - Not affected
Package: xchat (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://code.google.com/p/openjpeg/source/detail?r=1330http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082923.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/083105.htmlhttp://openjpeg.googlecode.com/svn/branches/openjpeg-1.5/NEWShttp://security.gentoo.org/glsa/glsa-201206-06.xmlhttp://technet.microsoft.com/en-us/security/msvr/msvr12-004http://www.securityfocus.com/bid/52654https://bugzilla.redhat.com/show_bug.cgi?id=805912http://code.google.com/p/openjpeg/source/detail?r=1330http://lists.fedoraproject.org/pipermail/package-announce/2012-June/082923.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-June/083105.htmlhttp://openjpeg.googlecode.com/svn/branches/openjpeg-1.5/NEWShttp://security.gentoo.org/glsa/glsa-201206-06.xmlhttp://technet.microsoft.com/en-us/security/msvr/msvr12-004http://www.securityfocus.com/bid/52654https://bugzilla.redhat.com/show_bug.cgi?id=805912
2012-04-11
Published