CVE-2014-8137

CWE-416Use After Free14 documents7 sources
Severity
6.8MEDIUM
EPSS
31.5%
top 3.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 24
Latest updateMay 14

Description

Double free vulnerability in the jas_iccattrval_destroy function in JasPer 1.900.1 and earlier allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ICC color profile in a JPEG 2000 image file.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages2 packages

Ubuntujasper< 1.900.1-14ubuntu3.2

Also affects: Enterprise Linux 6.0, 7.0

🔴Vulnerability Details

4
GHSA
GHSA-6c5f-g4r3-q34j: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 12022-05-14
OSV
jasper vulnerabilities2015-01-26
OSV
CVE-2014-8137: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 12014-12-24
CVEList
CVE-2014-8137: Double free vulnerability in the jas_iccattrval_destroy function in JasPer 12014-12-24

📋Vendor Advisories

4
Red Hat
jasper: double free issue in jas_iccattrval_destroy()2016-03-03
Ubuntu
Ghostscript vulnerabilities2015-01-26
Ubuntu
JasPer vulnerabilities2015-01-26
Red Hat
jasper: double-free in in jas_iccattrval_destroy() (oCERT-2014-012)2014-12-18

💬Community

5
Bugzilla
CVE-2014-8138 CVE-2014-8137 jasper: various flaws [epel-5]2014-12-18
Bugzilla
CVE-2014-8138 CVE-2014-8137 jasper: various flaws [fedora-all]2014-12-18
Bugzilla
CVE-2014-8138 CVE-2014-8137 mingw-jasper: various flaws [epel-7]2014-12-18
Bugzilla
CVE-2014-8138 CVE-2014-8137 mingw-jasper: various flaws [fedora-all]2014-12-18
Bugzilla
CVE-2014-8137 jasper: double-free in in jas_iccattrval_destroy() (oCERT-2014-012)2014-12-11
CVE-2014-8137 (MEDIUM CVSS 6.8) | Double free vulnerability in the ja | cvebase.io