CVE-2012-3535
published 2012-09-05CVE-2012-3535: Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute…
PriorityP434medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
6.15%
92.7th percentile
Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| uclouvain | openjpeg | <= 1.5 | — |
| uclouvain | openjpeg | — | — |
| uclouvain | openjpeg | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
openjpeg: heap-based buffer overflow when decoding jpeg2000 files
vendor_redhat·2012-08-27·CVSS 6.8
CVE-2012-3535 [MEDIUM] CWE-122 openjpeg: heap-based buffer overflow when decoding jpeg2000 files
openjpeg: heap-based buffer overflow when decoding jpeg2000 files
Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file.
GHSA
GHSA-cfh8-rvcx-v326: Heap-based buffer overflow in OpenJPEG 1
ghsa_unreviewed·2022-05-13
CVE-2012-3535 [MEDIUM] CWE-119 GHSA-cfh8-rvcx-v326: Heap-based buffer overflow in OpenJPEG 1
Heap-based buffer overflow in OpenJPEG 1.5.0 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted JPEG2000 file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3535 openjpeg: heap-based buffer overflow when decoding jpeg2000 files [fedora-all]
bugzilla·2012-08-27·CVSS 6.8
CVE-2012-3535 [MEDIUM] CVE-2012-3535 openjpeg: heap-based buffer overflow when decoding jpeg2000 files [fedora-all]
CVE-2012-3535 openjpeg: heap-based buffer overflow when decoding jpeg2000 files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/ne
Bugzilla
CVE-2012-3535 openjpeg: heap-based buffer overflow when decoding jpeg2000 files
bugzilla·2012-07-24·CVSS 6.8
CVE-2012-3535 [MEDIUM] CVE-2012-3535 openjpeg: heap-based buffer overflow when decoding jpeg2000 files
CVE-2012-3535 openjpeg: heap-based buffer overflow when decoding jpeg2000 files
A heap-based buffer overflow was found in the way OpenJPEG, an open-source JPEG 2000 codec written in C language, performed parsing of JPEG2000 image files. A remote attacker could provide a specially crafted JPEG 2000 file, which when opened in an application linked against openjpeg would lead to that application crash, or, potentially arbitrary code execution with the privileges of the user running the application.
Acknowledgements:
This issue was discovered by Huzaifa Sidhpurwala of the Red Hat Security Response Team.
Discussion:
Upstream bug:
http://code.google.com/p/openjpeg/issues/detail?id=170
---
This has been assigned CVE-2012-3535 via:
http://seclists.org/oss-sec/2012/q3/300
---
Created ope
http://code.google.com/p/openjpeg/issues/detail?id=170http://lists.fedoraproject.org/pipermail/package-announce/2012-October/090021.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090579.htmlhttp://osvdb.org/84978http://rhn.redhat.com/errata/RHSA-2012-1283.htmlhttp://secunia.com/advisories/50360http://secunia.com/advisories/50681http://www.mandriva.com/security/advisories?name=MDVSA-2012:157http://www.openwall.com/lists/oss-security/2012/08/27/2http://www.openwall.com/lists/oss-security/2012/08/27/3http://www.securityfocus.com/bid/55214https://bugzilla.redhat.com/show_bug.cgi?id=842918https://exchange.xforce.ibmcloud.com/vulnerabilities/77994http://code.google.com/p/openjpeg/issues/detail?id=170http://lists.fedoraproject.org/pipermail/package-announce/2012-October/090021.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2012-October/090579.htmlhttp://osvdb.org/84978http://rhn.redhat.com/errata/RHSA-2012-1283.htmlhttp://secunia.com/advisories/50360http://secunia.com/advisories/50681http://www.mandriva.com/security/advisories?name=MDVSA-2012:157http://www.openwall.com/lists/oss-security/2012/08/27/2http://www.openwall.com/lists/oss-security/2012/08/27/3http://www.securityfocus.com/bid/55214https://bugzilla.redhat.com/show_bug.cgi?id=842918https://exchange.xforce.ibmcloud.com/vulnerabilities/77994
2012-09-05
Published