CVE-2014-0158
published 2018-04-10CVE-2014-0158: Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash)…
PriorityP339high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
1.83%
76.4th percentile
Heap-based buffer overflow in the JPEG2000 image tile decoder in OpenJPEG before 1.5.2 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file because of incorrect j2k_decode, j2k_read_eoc, and tcd_decode_tile interaction, a related issue to CVE-2013-6045. NOTE: this is not a duplicate of CVE-2013-1447, because the scope of CVE-2013-1447 was specifically defined in http://openwall.com/lists/oss-security/2013/12/04/6 as only "null pointer dereferences, division by zero, and anything that would just fit as DoS."
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| uclouvain | openjpeg | < 1.5.2 | 1.5.2 |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0158 openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [fedora-all]
bugzilla·2014-04-01·CVSS 5.0
CVE-2014-0158 [MEDIUM] CVE-2014-0158 openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [fedora-all]
CVE-2014-0158 openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please not
Bugzilla
CVE-2014-0158 mingw-openjpeg: openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [fedora-all]
bugzilla·2014-04-01·CVSS 8.8
CVE-2014-0158 [HIGH] CVE-2014-0158 mingw-openjpeg: openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [fedora-all]
CVE-2014-0158 mingw-openjpeg: openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availa
Bugzilla
CVE-2014-0158 openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [epel-5]
bugzilla·2014-04-01·CVSS 8.8
CVE-2014-0158 [HIGH] CVE-2014-0158 openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [epel-5]
CVE-2014-0158 openjpeg: Heap-based buffer overflow in JPEG2000 image tile decoder [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
epel-5 tr
Bugzilla
CVE-2014-0154 ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
bugzilla·2014-03-28·CVSS 5.0
CVE-2014-0154 [MEDIUM] CVE-2014-0154 ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
CVE-2014-0154 ovirt-engine-webadmin: HttpOnly flag is not included when the session ID is set
It was found that the oVirt web admin interface did not include the HttpOnly flag when setting session IDs with the Set-Cookie header. As a result, it is easier for remote attackers to hijack an oVirt web admin session by leveraging a cross-site scripting (XSS) vulnerability.
Discussion:
Upstream bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1077450
Upstream patch commit:
http://gerrit.ovirt.org/#/c/25915/
---
Created ovirt-engine tracking bugs for this issue:
Affects: fedora-all [bug 1081929]
---
This issue has been addressed in the following products:
RHEV Manager version 3.5
Via RHSA-2015:0158 https://rhn.redhat.com/errata/RHSA-2015-0158.html
Bugzilla
CVE-2014-0151 ovirt-engine: cross-site request forgery (CSRF)
bugzilla·2014-03-28·CVSS 6.8
CVE-2014-0151 [MEDIUM] CVE-2014-0151 ovirt-engine: cross-site request forgery (CSRF)
CVE-2014-0151 ovirt-engine: cross-site request forgery (CSRF)
The oVirt REST API is vulnerable to Cross-Site Request Forgery (CSRF) attacks. A remote attacker could provide a specially-crafted web page that, when visited by a user with a valid REST API session, would allow the attacker to trigger calls to the oVirt REST API.
Discussion:
Upstream bug:
https://bugzilla.redhat.com/show_bug.cgi?id=1077441
---
Created ovirt-engine tracking bugs for this issue:
Affects: fedora-all [bug 1081906]
---
Note that the same vulnerability affects the oVirt backend/GUI, as an attacker can also craft a request for the GWT RPC servlet using the same method.
---
This issue has been addressed in the following products:
RHEV Manager version 3.5
Via RHSA-2015:0158 https://rhn.redhat.com/errata/RHS
2018-04-10
Published